SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11776

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter.

MEDIUM 6.1EPSS 0.90%

Does this matter?

Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.

Description

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.90% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
eclipse/business intelligence and reporting tools
Source
emo@eclipse.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.