Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29627 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library |
Github GHSA |
GHSA-7c3f-cg9x-f3gr | JasperReports has a Java deserialisation vulnerability |
Tue, 10 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloud
Cloud jasperreports Io Cloud jasperreports Library Cloud jasperreports Server Cloud jasperreports Studio Cloud jasperreports Web Studio |
|
| CPEs | cpe:2.3:a:cloud:jasperreports_io:*:*:*:*:at-scale:*:*:* cpe:2.3:a:cloud:jasperreports_io:*:*:*:*:professional:*:*:* cpe:2.3:a:cloud:jasperreports_library:*:*:*:*:community:*:*:* cpe:2.3:a:cloud:jasperreports_library:*:*:*:*:professional:*:*:* cpe:2.3:a:cloud:jasperreports_server:*:*:*:*:*:*:*:* cpe:2.3:a:cloud:jasperreports_studio:*:*:*:*:community:*:*:* cpe:2.3:a:cloud:jasperreports_studio:*:*:*:*:professional:*:*:* cpe:2.3:a:cloud:jasperreports_web_studio:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cloud
Cloud jasperreports Io Cloud jasperreports Library Cloud jasperreports Server Cloud jasperreports Studio Cloud jasperreports Web Studio |
|
| Metrics |
cvssV3_1
|
Thu, 25 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
ssvc
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jaspersoft
Jaspersoft jasperreports |
|
| Vendors & Products |
Jaspersoft
Jaspersoft jasperreports |
Tue, 16 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library | |
| Title | Jaspersoft Library Deserialisation Vulnerability | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Jaspersoft
Published:
Updated: 2026-02-10T18:12:20.433Z
Reserved: 2025-09-15T16:26:21.449Z
Link: CVE-2025-10492
Updated: 2025-09-25T16:15:15.782Z
Status : Modified
Published: 2025-09-16T17:15:40.517
Modified: 2026-02-10T19:15:49.760
Link: CVE-2025-10492
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:52:05Z
EUVD
Github GHSA