CVE Database
/

CVE-2021-34427

Back to search

CVE-2021-34427

Published: Jun 25, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

VendorProductVersions

The Eclipse Foundation

Eclipse BIRT

affected
unspecified - <= 4.8.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now