A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
| Software | From | Fixed in |
|---|---|---|
| cloud / jasperreports_io | - | 4.0.0.x |
| cloud / jasperreports_library | - | 7.0.3.x |
| cloud / jasperreports_library | - | 9.0.2.x |
| cloud / jasperreports_server | - | 9.0.0.x |
| cloud / jasperreports_studio | - | 7.0.3.x |
| cloud / jasperreports_studio | - | 9.0.2.x |
| cloud / jasperreports_web_studio | - | 3.0.1.x |