Red Hat Bugzilla – Bug 1510332
CVE-2017-14941 jasperreports: Cleartext storage of passwords
Last modified: 2018-02-12 04:00:23 EST
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector. References: https://github.com/binary1985/VulnerabilityDisclosure/blob/master/JasperSoft%20JasperReports%20-%204.7%20-%20CVE-2017-14941
Statement: Red Hat Product Security is not aware of any supported product that ships the affected component.