PT-2025-54691 · Maven · Net.Sf.Jasperreports:Jasperreports

Published

2025-09-16

·

Updated

2025-09-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A Java deserialisation vulnerability has been discovered in the Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-7C3F-CG9X-F3GR

Affected Products

Net.Sf.Jasperreports:Jasperreports