Credential Disclosure in Jaspersoft JasperReports by TIBCO Software
CVE-2017-14941
6.5MEDIUM
What is CVE-2017-14941?
Jaspersoft JasperReports 4.7 presents a saved credential disclosure vulnerability, enabling a remote authenticated user to access sensitive Data Source passwords. By executing an Edit action on a Data Source connector and analyzing the HTML source of the resulting flow.html page, unauthorized retrieval of these credentials can occur, potentially compromising data security within applications using this reporting tool.
