Vulnerabilities > Eclipse > Business Intelligence AND Reporting Tools > 2.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-06-25 CVE-2021-34427 Unrestricted Upload of File with Dangerous Type vulnerability in Eclipse Business Intelligence and Reporting Tools
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
network
low complexity
eclipse CWE-434
critical
9.8
2019-08-09 CVE-2019-11776 Cross-site Scripting vulnerability in Eclipse Business Intelligence and Reporting Tools
In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter.
network
eclipse CWE-79
4.3