Executive brief
Jaspersoft Reports, a widely used Java reporting library, is vulnerable to a security flaw that could allow an attacker to take control of the server. By sending specially crafted data, an attacker with low-level access can execute unauthorized commands on the system. This could lead to the theft of sensitive business data, service disruptions, or full system compromise.
Technical details
A Java Deserialization vulnerability (CWE-502) exists in the Jaspersoft Reports Library (net.sf.jasperreports:jasperreports) in versions prior to 7.0.7. The flaw occurs when the library processes untrusted serialized data, allowing an attacker to trigger remote code execution (RCE). Exploitation requires network access and low-level privileges (PR:L) but no user interaction. Successful exploitation grants the attacker high impact over confidentiality, integrity, and availability of the affected system. The issue is resolved in version 7.0.7.
Affected products
- Jaspersoft JasperReports Library < 7.0.7
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-07-10: patched: Advisory updated with patch information