CVE-2025-10492
EUVD-2025-2962716.09.2025, 17:15
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected libraryEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cloud | jasperreports_io | 𝑥 ≤ 4.0.0 |
| cloud | jasperreports_io | 𝑥 ≤ 4.0.0 |
| cloud | jasperreports_library | 𝑥 ≤ 7.0.3 |
| cloud | jasperreports_library | 𝑥 ≤ 9.0.2 |
| cloud | jasperreports_server | 𝑥 ≤ 9.0.0 |
| cloud | jasperreports_studio | 𝑥 ≤ 7.0.3 |
| cloud | jasperreports_studio | 𝑥 ≤ 9.0.2 |
| cloud | jasperreports_web_studio | 𝑥 ≤ 3.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration