Back

MEDIUM

jasperreports: Cleartext storage of passwords

Published Oct 1, 2017

Description

Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.

Affected products

Remediation

Red Hat statement

Red Hat Product Security is not aware of any supported product that ships the affected component.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 1, 2017
Updated Aug 5, 2024
Reserved Sep 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 30, 2017