CVE-2021-34427
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
- Affected products
- Eclipse Birt
- Eclipse Business Intelligence And Reporting Tools
- ≤ 4.8.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 58.0% (99th percentile)
- Weakness
- CWE-434, CWE-20
- NVD status
- Modified
- Published
- 2021-06-25
CVE-2021-34427 at NVD
3 known exploits for CVE-2021-34427
Proof-of-concept code and exploit modules indexed by Sploitus