VYPR

Jasperreports

by Jaspersoft

CVEs (1)

  • CVE-2017-14941MedOct 2, 2017
    risk 0.42cvss 6.5epss 0.00

    Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.