RSS   Vulnerabilities for 'Jasperreports'   RSS

2017-10-01
 
CVE-2017-14941

 

 
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.

 


Copyright 2024, cxsecurity.com

 

Back to Top