Showing 2 vulnerabilities on this page for Eclipse BIRT

Signals CISA KEV Ransomware Nuclei
The Eclipse Foundation vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

eclipse business_intelligence_and_reporting_tools Improper Input Validation

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

CWE-20CWE-434Jun 25, 20211 related artifact
CVSS9.8v3.1EPSS58%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

CWE-79Aug 9, 2019
CVSS6.1v3.1EPSS0.897%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX