CVE-2025-10492

Published Sep 16, 2025

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-10492 is a Java deserialization vulnerability identified in the Jaspersoft Library. This flaw stems from the improper handling of externally supplied data during the deserialization process, which can allow attackers to execute arbitrary code remotely on systems utilizing the affected library. The vulnerability impacts various Jaspersoft products, including JasperReports Library (Community & Professional editions), JasperReports Server, JasperReports Studio, and JasperReports IO editions. Exploitation typically involves providing malicious JRXML report templates or compiled `.jasper` report templates, which, when loaded and deserialized by the application, can lead to remote code execution.

Description
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
Source
db6d2600-d19b-4111-a010-f3c4ed70cd50
NVD status
Modified
Products
jasperreports_io, jasperreports_library, jasperreports_server, jasperreports_studio, jasperreports_web_studio

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

db6d2600-d19b-4111-a010-f3c4ed70cd50
CWE-502
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-502

Social media

Hype score
Not currently trending
  1. ๐Ÿ”’ #CyberSecurity Critical CVE-2025-10492: Mitigating Unauthenticated RCE in Hitachi Energy Ellipโ€ฆ "Security teams managing Operational Technology (OT) and Critical Manufacturing environmentsโ€ฆ" ๐Ÿ”— https://t.co/I80reOj0LP #CyberSecurity #ThreatIntel #vulnerability #cve

    @SecurityAr58409

    15 Apr 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Attackers exploiting CVE-2025-10492 in Hitachi Energy's Ellipse platform can achieve unauthenticated remote code execution, then escalate privileges and move laterally across enterprise networks. Runtime segmentation helps limit blast radius when critical infrastructure systems

    @aviatrixtrc

    3 Apr 2026

    131 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. โš ๏ธ **Vulnerability Alert:** Jaspersoft Java Deserialization RCE in Hitachi Energy Ellipse (CVE-2025-10492) ๐Ÿ†” **CVE-2025-10492** | ๐Ÿ“Š CVSS: 9.8 (Critical ๐Ÿ”ด) | ๐Ÿ“ˆ EPSS: 59.43% ๐Ÿ› ๏ธ **Exploit Maturity:** Not Available ๐Ÿ“‚ **Affected Versions:** Ellipse <= 9.0.

    @syedaquib77

    2 Apr 2026

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. โš ๏ธ **Vulnerability Alert:** Hitachi Energy Ellipse Jaspersoft Java Deserialization Remote Code Execution ๐Ÿ“… **Timeline:** Disclosure: N/A, Patch: N/A ๐Ÿ†” **CVE-2025-10492** | ๐Ÿ“Š CVSS: 9.8 (Critical ๐Ÿ”ด) | ๐Ÿ“ˆ EPSS: 59.43% ๐Ÿ› ๏ธ **Exploit Maturity:** Not Available

    @syedaquib77

    2 Apr 2026

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. โš ๏ธ **Vulnerability Alert:** Hitachi Energy Ellipse Jaspersoft Java Deserialization RCE (CVE-2025-10492) ๐Ÿ“… **Timeline:** Disclosure: Not Available; Patch: Not Available ๐Ÿ†” **CVE-2025-10492** | ๐Ÿ“Š CVSS: 9.8 (Critical ๐Ÿ”ด) | ๐Ÿ“ˆ EPSS: 59.43% ๐Ÿ› ๏ธ **Exploit Maturity

    @syedaquib77

    2 Apr 2026

    127 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. โš ๏ธ **Vulnerability Alert:** Hitachi Energy Ellipse - Jaspersoft Java Deserialization RCE (CVE-2025-10492) ๐Ÿ“… **Timeline:** Disclosure: Unknown, Patch: Unknown ๐Ÿ†” **CVE-2025-10492** | ๐Ÿ“Š CVSS: 9.8 (Critical ๐Ÿ”ด) | ๐Ÿ“ˆ EPSS: 59.43% ๐Ÿ› ๏ธ **Exploit Maturity:** Not Av

    @syedaquib77

    2 Apr 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. โš ๏ธ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Ellipse JasperReports RCE; Siemens SICAM 8 DoS/Out-of-bounds; Yokogawa CENTUM VP Hard-coded Password ๐Ÿ“… **Timeline:** Disclosure: unknown, Patch: unknown ๐Ÿ†” **CVE-2025-10492** | ๐Ÿ“Š CVSS: 9.8 (Critical

    @syedaquib77

    2 Apr 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. โš ๏ธ **Vulnerability Alert:** Jaspersoft (Jasper Report) Java Deserialization RCE in Hitachi Energy Ellipse (CVE-2025-10492) ๐Ÿ“… **Timeline:** Not Available ๐Ÿ†” **CVE-2025-10492** | ๐Ÿ“Š CVSS: 9.8 (Critical ๐Ÿ”ด) | ๐Ÿ“ˆ EPSS: 59.43% ๐Ÿ› ๏ธ **Exploit Maturity:** Not Availab

    @syedaquib77

    2 Apr 2026

    115 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. โš ๏ธ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password ๐Ÿ“… **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30 ๐Ÿ†” **CVE-2025

    @syedaquib77

    2 Apr 2026

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Hitachi Energy Asset Suite versions 9.7 and earlier have a Java deserialization flaw (CVE-2025-10492) via Jasper Report, allowing remote code execution. Network segmentation and firewalls are recommended. #EnergySecurity #JavaFlaw #USA https://t.co/D4cOzDmDjd

    @TweetThreatNews

    10 Jan 2026

    111 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2025-10492: How a Third-Party Library Exposed the Core of Hitachi Energyโ€™s Asset Suite Read the full report on - https://t.co/nFTJbZBkXy https://t.co/8YQkQYhNNd

    @cyberbivash

    10 Jan 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Jaspersoft Jasper Reports JRLoader Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-10492) #CVE202510492 #CyberSecurity #Jaspersoft #RemoteCodeExecutionVulnerability https://t.co/SFQXdf0pAb https://t.co/dKSqohi3pd

    @SystemTek_UK

    11 Oct 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2025-10492 Java Deserialization Remote Code Execution in Jaspersoft Library https://t.co/Mqc2zYye0A

    @VulmonFeeds

    17 Sept 2025

    74 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations