Jump to content
We've recently updated our Privacy Statement, available here ×

Security vulnerability CVE-2020-9410 for jasper-report library v6.8.1


Sameer Mandaokar
Go to solution Solved by djohnson53,

Recommended Posts

Hi All,

We're using standalone jasperreports library v6.8.1(community edition) in embedded mode with our product. As per published CVE-2020-9410, it seems all the jasperreports version 7.1.1 and below are vulnerable for this security issue. Can you please confirm if this is applicable for jasperreport library 6.8.1 when used inside application which doesn't uses Jasper's HTML component to render the report-output? If yes, then which version of jasperreports library wil fix this issue and what is the release date for this? WIll there be any patch for existing versions like v6.8.1.

 

Thanks, 

Sameer Mandaokar

Link to comment
Share on other sites

  • 2 weeks later...
  • Replies 4
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Anybody can confirm?

OWASP dependency scan detected high severity but low confidence level. Currently, the maven repository the highest level is 6.12.2. No release note information indicate it is fixing the CVE issue. 

Link to comment
Share on other sites

  • Solution

Please refer to these resources.  As TIBCO employees, we are not at liberty to discuss these CVE's outside of these resources:

Security Advisories

TIBCO distributes information about security vulnerabilities and remediation in its products through security advisories.

Public Security Notices

TIBCO’s response to general publicly announced security issues can be found on our Public Notices page.

 

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×
×
  • Create New...