CVE-2025-10492

CRITICAL

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that ...

Affects 5 products across 1 vendor.

BCS7.13
CVSS 3.19.8
CVSS v48.7
EPSS0.9%
Percentile56th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-502: Deserialization of Untrusted Data

Software deserializes untrusted data without validation, allowing crafted objects to execute arbitrary code.

Related Attack Patterns (CAPEC)
CAPEC-586 Object Injection
via CWE-502

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical Java deserialization vulnerability in Jaspersoft Library allows remote attackers to execute arbitrary code due to improper handling of externally supplied data.

BSID: BS-2025-GLOBAL-228850-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-10492?
A critical Java deserialization vulnerability in Jaspersoft Library allows remote attackers to execute arbitrary code due to improper handling of externally supplied data.
What is the CVSS score for CVE-2025-10492?
CVE-2025-10492 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.9%.
Is CVE-2025-10492 actively exploited?
No confirmed active exploitation of CVE-2025-10492 as of 2026-05-30.
How do I remediate CVE-2025-10492?
Priority: IMMEDIATE. Advisory: https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-september-16-2025-jaspersoft-library-cve-2025-10492-r6/ PSIRT: db6d2600-d19b-4111-a010-f3c4ed70cd50
What systems are affected by CVE-2025-10492?
CVE-2025-10492 affects: Cloud, Cloud, Cloud, Cloud, Cloud.
Vulnerability Details
CVE IDCVE-2025-10492
BSIDBS-2025-GLOBAL-228850-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-09-16
Last Modified2026-02-10
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the Jaspersoft Library's failure to properly validate and sanitize serialized objects before deserialization. An attacker can exploit this by sending maliciously crafted serialized data to a vulnerable system, leading to remote code execution.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cloud Jasperreports Server
Cloud Jasperreports Io
Cloud Jasperreports Library
Cloud Jasperreports Studio
Cloud Jasperreports Web Studio
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: db6d2600-d19b-4111-a010-f3c4ed70cd50
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 333 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash7ddc06b1759b85d27e4d581aa14a016a55fe71a7d6aa7d0abb3b3777d9b3974ec0901f67949b3df62a26a9f402c5ac0c4e95f12f3e5bf129e4b9f19ba9907b0e
Related CVEs affecting Cloud
CVE-2025-54122 10.0 Manager-io/Manager is accounting software. A critical unauthenticated full re... CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2025-64180 10.0 Manager-io/Manager is accounting software. In Manager Desktop and Server vers... CVE-2026-0501 9.9 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Prem... CVE-2025-47282 9.9 Gardener External DNS Management is an environment to manage external DNS ent...
View all Cloud CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →