First published: Mon Oct 02 2017(Updated: )
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jaspersoft JasperReports | =4.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.