← Back

CVE-2025-10492

nvd nist
Published: Sep 16, 2025Modified: Feb 10, 2026

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: db6d2600-d19b-4111-a010-f3c4ed70cd50 (Secondary)

Description

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library

Affected (8)

5 products
Jasperreports Io
Jasperreports Library
Jasperreports Server
Jasperreports Studio
Jasperreports Web Studio
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Cloud
Up to 4.0.0
Up to 4.0.0
Cloud
Up to 7.0.3
Up to 9.0.2
Up to 9.0.0
Cloud
Up to 7.0.3
Up to 9.0.2
Up to 3.0.1

Timeline

No history available yet.