ZDI-CAN-27130: ZDI-25-948: Jaspersoft Jasper Reports JRLoader Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Jaspersoft Jasper Reports. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-10492.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27130?
The severity of ZDI-CAN-27130 is critical due to its potential for remote code execution.
How do I fix ZDI-CAN-27130?
To fix ZDI-CAN-27130, update Jaspersoft Jasper Reports to the latest version provided by the vendor.
What kind of attacks can exploit ZDI-CAN-27130?
ZDI-CAN-27130 can be exploited through various attack vectors that interact with the affected library.
Who is affected by ZDI-CAN-27130?
Users of Jaspersoft Jasper Reports are affected by ZDI-CAN-27130, particularly those with vulnerable installations.
Is ZDI-CAN-27130 being actively exploited?
There is a risk that ZDI-CAN-27130 could be actively exploited in the wild, emphasizing the need for prompt remediation.