CVE-2025-10492
CVSS 9.8 CRITICAL: a Java deserialisation vulnerability has been discovered in Jaspersoft Library. EPSS 0.9% (58th percentile).
Vulnerabilities & Exploits · Web App Attack
Hitachi Energy Ellipse versions 9.0.50 and earlier include a vulnerable JasperReports library with a Java deserialization flaw (CVE-2025-10492). This flaw allows remote attackers to execute arbitrary code by exploiting the report generation feature. The vulnerability lies in a third-party component used for custom reports, not the core Ellipse application itself.
Because the exploit targets the reporting endpoints, network controls alone do not prevent attacks. Operators must update Ellipse to a fixed version or apply vendor mitigations such as disabling external report loading or restricting report access. This is critical for organizations in manufacturing and critical infrastructure sectors using Ellipse worldwide.
1 source · Apr 2
CVSS 9.8 CRITICAL: a Java deserialisation vulnerability has been discovered in Jaspersoft Library. EPSS 0.9% (58th percentile).
CISA Advisories
Hitachi Energy Ellipse | CISA
Hitachi Energy Ellipse Summary Hitachi Energy is aware of a Jasper Report vulnerability that affects the Ellipse product versions mentioned in this document below.
originalPart of the PlainSec briefing for 2026-04-03
Every edition of this story: Java Deserialization RCE in Hitachi Energy Ellipse Reporting Component