SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-10492

A Java deserialisation vulnerability has been discovered in Jaspersoft Library.

HIGH 8.7EPSS 0.91%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library

CVSS 4.0
8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.91% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
cloud/jasperreports io · cloud/jasperreports library · cloud/jasperreports server · cloud/jasperreports studio · cloud/jasperreports web studio
Source
db6d2600-d19b-4111-a010-f3c4ed70cd50

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.