SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
38 stars 0 forks source link

[FullDisclosure] [SYSS-2022-041] Remote Code Execution due to unsafe JMX default configuration in JasperReports Server #2523

Closed github-actions[bot] closed 2 years ago

github-actions[bot] commented 2 years ago

Posted by Moritz Bechler on Sep 12

Advisory ID: SYSS-2022-041

Product: JasperReports Server

Manufacturer: TIBCO Software Inc.

Tested Version(s): 8.0.2 Community Edition

Vulnerability Type: CWE-502: Deserialization of Untrusted Data

Risk Level: High

Solution Status: Fixed

Manufacturer Notification: 2022-06-10

Solution Date: 2022-08-10

Public Disclosure: 2022-09-09

CVE Reference:...

https://seclists.org/fulldisclosure/2022/Sep/11

github-actions[bot] commented 2 years ago

This issue is stale because it has been open 1 day with no activity. Remove stale label or comment or this will be closed in 1 day.

github-actions[bot] commented 2 years ago

This issue was closed because it has been stale with no activity.