Skip to content

Is JasperReportsIntegration really vulnarable to CVE-2025-48734 (8.8) #157

@sweco-nldaan

Description

@sweco-nldaan

Accoording to NVD - CVE-2025-48734 the commons-beanutils-1.9.4 should be upgraded to commons-beanutils-1.11.0. Although commons-beanutils-1.9.4 already enables the protection by default the National Vulnerability Database is advicing us to update to version 1.11.0.

Is this this really necessary?

Environment:
JasperReportsIntegration (2.11.0) on Tomcat 9
Oracle linux 8
Java 11

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions