Bug 409439 - Security Vulnarabilities in BIRT 4.2.2
Summary: Security Vulnarabilities in BIRT 4.2.2
Status: NEW
Alias: None
Product: z_Archived
Classification: Eclipse Foundation
Component: BIRT (show other bugs)
Version: 4.2.2   Edit
Hardware: PC Linux
: P3 major (vote)
Target Milestone: ---   Edit
Assignee: Birt-ReportEngine-inbox@eclipse.org CLA
QA Contact:
URL:
Whiteboard:
Keywords: security
Depends on:
Blocks:
 
Reported: 2013-05-29 20:18 EDT by Bill Thrall CLA
Modified: 2020-01-10 11:38 EST (History)
1 user (show)

See Also:


Attachments
List of issues found in BIRT jar files (19.18 KB, application/vnd.openxmlformats-officedocument.spreadsheetml.sheet)
2013-05-29 20:19 EDT, Bill Thrall CLA
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Bill Thrall CLA 2013-05-29 20:18:05 EDT
We have integrated the BIRT viewer and report engine into an internal GE Capital application to generate a context-sensitive report from application data.  When we had the GE Security COE run a mandatory bi-annual security scan on the application code, they flagged a total of 103 instances across 11 types of vulnerabilities and code issues within the BIRT library included in our code base.  
Attached is the summary of the BIRT-related findings from that security review.  I need to know ASAP which of these items you are both willing and able to resolve, and the timeline for that remediation effort, plus explanations as to why you cannot resolve any that you don't plan to remediate as we are required to get all identified vulnerabilities remediated if possible.
Note that some of these vulnerabilities may actually be false positives, and that is a valid explanation if that is truly the case; you are certainly not obligated to cripple the tool to 'resolve' valid and necessary sections of code.
Comment 1 Bill Thrall CLA 2013-05-29 20:19:21 EDT
Created attachment 231730 [details]
List of issues found in BIRT jar files