← back
CVE-2021-34427observed exploitationCWE-20

CVE-2021-34427

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 58%
from disclosure to weapon1818 days
Published on NVDJun 25
1st PoC+1818d
VulnCheck+1635d
exploitation probability
58%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.