First published: Wed Apr 09 2014(Updated: )
The Red Hat Enterprise Virtualization reports package provides a suite of<br>pre-configured reports and dashboards that enable you to monitor the<br>system. The reports module is based on JasperReports and JasperServer, and<br>can also be used to create ad-hoc reports.<br>XStream is a simple library used by the Red Hat Enterprise Virtualization<br>reports package to serialize and de-serialize objects to and from XML.<br>It was found that XStream could deserialize arbitrary user-supplied XML<br>content, representing objects of any type. A remote attacker able to pass<br>XML to XStream could use this flaw to perform a variety of attacks,<br>including remote code execution in the context of the server running the<br>XStream application. (CVE-2013-7285)<br>All jasperreports-server-pro users are advised to upgrade to this updated<br>package, which contains a backported patch to correct this issue.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jasperreports-server-pro | <5.5.0-6.el6e | 5.5.0-6.el6e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.