CVE-2025-10492
Published: Sep 16, 2025
Modified: Feb 10, 2026
Description
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
| Vendor | Product | Versions |
|---|---|---|
Jaspersoft | JasperReports Library Community Edition | affected 0 - <= 7.0.3 |
Jaspersoft | Jaspersoft Studio Community Edition | affected 0 - <= 7.0.3 |
Jaspersoft | JasperReports Server | affected 0 - <= 9.0.0 |
Jaspersoft | JasperReports Library Professional | affected 0 - <= 9.0.2 |
Jaspersoft | Jaspersoft Studio Professional | affected 0 - <= 9.0.2 |
Jaspersoft | JasperReports IO Professional | affected 0 - <= 4.0.0 |
Jaspersoft | JasperReports IO At-Scale | affected 0 - <= 4.0.0 |
Jaspersoft | JasperReports Web Studio | affected 0 - <= 3.0.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now