Vulnerabilities · 183 days ago

Java Deserialization RCE in Hitachi Energy Ellipse Reporting Component

Hitachi Energy Ellipse versions 9.0.50 and earlier include a vulnerable JasperReports library with a Java deserialization flaw (CVE-2025-10492). This flaw allows remote attackers to execute arbitrary code by exploiting the report generation feature. The vulnerability lies in a third-party component used for custom reports, not the core Ellipse application itself.

Because the exploit targets the reporting endpoints, network controls alone do not prevent attacks. Operators must update Ellipse to a fixed version or apply vendor mitigations such as disabling external report loading or restricting report access. This is critical for organizations in manufacturing and critical infrastructure sectors using Ellipse worldwide.

CVE-2025-10492

NVD KEV

CVSS 9.8 CRITICAL: a Java deserialisation vulnerability has been discovered in Jaspersoft Library. EPSS 0.9% (58th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-04-03

Editions

Related stories