Unrated severityNVD Advisory· Published Sep 20, 2011· Updated Apr 29, 2026
CVE-2011-1911
CVE-2011-1911
Description
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
Affected products
2cpe:2.3:a:jasperforge:jasperreports_server_community_project:3.7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jasperforge:jasperreports_server_community_project:3.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:jasperforge:jasperreports_server_community_project:3.7.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.kb.cert.org/vuls/id/519588nvdUS Government Resource
- www.kb.cert.org/vuls/id/MAPG-8ELLJCnvdUS Government Resource
- www.csirtcv.gva.es/es/alertas/vulnerabilidad-en-jasperserver.htmlnvd
- www.csirtcv.gva.es/sites/all/files/images/content/%5BCSIRT-cv%5D%20JasperServer%203.7.0%20CE%20CSRF%20Advisory.pdfnvd
- www.securityfocus.com/bid/49649nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/69849nvd
News mentions
0No linked articles in our index yet.