CVE-2025-41254 Vulnerability in JasperReports Server
search cancel

CVE-2025-41254 Vulnerability in JasperReports Server

book

Article ID: 444301

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager CA Service Desk Manager

Issue/Introduction

A security vulnerability (CVE-2025-41254) has been identified in the JasperReports Server. The vulnerability is related to the spring-core-5.3.45.jar file located in the JasperReports Server directories.

Vulnerable Path: jasperserver-pro\WEB-INF\lib\spring-core-5.3.45.jar

Installed Version: 5.3.45 (or earlier, e.g., 5.3.29)
Target Fixed Version: 5.3.46 or later

Environment

Product: Service Management 

Component: JasperReports Server 9.0.0

Cause

The issue is caused by a 3rd party vulnerability in the Spring Framework (CVE-2025-41254) affecting versions prior to 5.3.46. While JasperReports Server is not a WebSocket application and is not directly exploitable via STOMP CSRF, a fix is required to update the library to a non-vulnerable version.

Resolution

Broadcom has certified a cumulative hotfix for JasperReports Server that includes spring-core-5.3.47.jar, resolving the vulnerability.

1. Download the cumulative hotfix hotfix_JRSPro9.0.0_cumulative_20260529_0146 (T5UG606.caz) from the Broadcom Support Portal: Download Fix (APAR 99112752)

2. Follow the installation instructions provided in the T5UG606_Readme.txt file included with the hotfix.

3. Verify the spring-core jar version in the following path has been updated to 5.3.47 or higher: ...\WEB-INF\lib\spring-core-5.3.47.jar

Additional Information

Integrate JasperReports Server 9.0.0 with CA Service Management