CVE-2019-11776: Eclipse Business Intelligence And Reporting Tools

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

Affected products

  • Eclipse Business Intelligence And Reporting Tools: from 1.0.0, up to and including 4.7.0

Published 2019-08-09. Last modified 2026-06-17.