A vulnerability was found in Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context. Reference: https://bugs.eclipse.org/bugs/show_bug.cgi?id=546816
Upstream fix: https://github.com/eclipse/birt/commit/91ef71824fa33d8fad5da1f7f23791a37f9aa4dc
Statement: This flaw did not affect the versions of eclipse-birt as shipped with Red Hat Enterprise Linux 6, as they did not include the BIRT Viewer component.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11776