A security vulnerability (CVE-2025-41254) has been identified in the JasperReports Server. The vulnerability is related to the spring-core-5.3.45.jar file located in the JasperReports Server directories.
Vulnerable Path: jasperserver-pro\WEB-INF\lib\spring-core-5.3.45.jar
Installed Version: 5.3.45 (or earlier, e.g., 5.3.29)
Target Fixed Version: 5.3.46 or later
Product: Service Management
Component: JasperReports Server 9.0.0
The issue is caused by a 3rd party vulnerability in the Spring Framework (CVE-2025-41254) affecting versions prior to 5.3.46. While JasperReports Server is not a WebSocket application and is not directly exploitable via STOMP CSRF, a fix is required to update the library to a non-vulnerable version.
Broadcom has certified a cumulative hotfix for JasperReports Server that includes spring-core-5.3.47.jar, resolving the vulnerability.
1. Download the cumulative hotfix hotfix_JRSPro9.0.0_cumulative_20260529_0146 (T5UG606.caz) from the Broadcom Support Portal: Download Fix (APAR 99112752)
2. Follow the installation instructions provided in the T5UG606_Readme.txt file included with the hotfix.
3. Verify the spring-core jar version in the following path has been updated to 5.3.47 or higher: ...\WEB-INF\lib\spring-core-5.3.47.jar