CVE-2017-14941

MEDIUM

Jaspersoft Jasperreports - Information Disclosure

Title source: rule
STIX 2.1

Description

Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.

Scores

CVSS v3 6.5
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
jaspersoft/jasperreports 4.7.0
Published Oct 02, 2017
Tracked Since Feb 18, 2026