Impact
Jaspersoft JasperReports Server is vulnerable to an XXE injection flaw that allows unauthenticated attackers to supply malicious XML documents containing external entity references. Exploiting this weakness can enable the attacker to read arbitrary files on the server, achieve denial‑of‑service conditions, or potentially execute code with the privileges of the server process, as documented under CWE-611.
Affected Systems
The vulnerability affects Jaspersoft JasperReports Server versions 9.0.0 through the last release before HF‑9, as well as all 10.0.0 releases prior to HF‑10. Any instance of these product versions that has not received the corresponding hot‑fix is considered susceptible.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity with full network scope and no requirement for user interaction. Although the EPSS score is not provided, the absence from the CISA KEV catalog does not diminish the exploitability risk. Because the vulnerability is unauthenticated, an attacker who can reach the server endpoint can trigger it simply by uploading a crafted XML file, making the attack vector likely to be local or network based with direct interaction to the server, not requiring any privileged access.
OpenCVE Enrichment