Java Deserialization Vulnerability in Jaspersoft Library by TIBCO Software
CVE-2025-10492
What is CVE-2025-10492?
A vulnerability in the Jaspersoft Library allows for Java deserialization issues, which can result in improper handling of external data. This puts systems using the library at risk of remote code execution by malicious actors. Users are urged to implement the latest security measures to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
JasperReports IO At-Scale 0 <= 4.0.0
JasperReports IO Professional 0 <= 4.0.0
JasperReports Library Community Edition 0 <= 7.0.3
News Articles
Jaspersoft Jasper Reports JRLoader Deserialization Of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-10492)
- This vulnerability allows remote attackers to execute arbitrary code on affected installations of Jaspersoft Jasper Reports.
References
CVSS V4
Timeline
- ๐ฐ
First article discovered by systemtek.co.uk
Vulnerability published
Vulnerability Reserved
