In Eclipse BIRT 4.8.0 and earlier, an attacker can abuse query parameters to cause creation of a JSP file within the current BIRT viewer directory. Because the created file is remotely accessible and its contents can include attacker-controlled JSP code, the flaw enables server-side code injection and execution within the running BIRT instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC consisting of one Python script and a short README. The main file, CVE-2021-34427.py, targets CVE-2021-34427 in Eclipse BIRT Viewer and implements a full exploitation chain rather than simple detection. It abuses the /reports/document endpoint by sending a GET request with __report=test.rptdesign, a sample parameter containing attacker-controlled JSP code, and a crafted __document value of the form ./<name>.jsp/. to bypass extension checks. The intended effect is to write a JSP webshell into the web-accessible /reports directory. After writing the shell, the script immediately requests /reports/<random>.jsp with a cmd query parameter to execute an arbitrary command. The embedded JSP payload is Windows-specific because it invokes cmd.exe /c. The script uses requests with TLS verification disabled, sets a browser-like User-Agent, generates a random 8-character JSP filename, and includes a clean_output() helper that strips common BIRT/RPTDOC binary/report noise from the HTTP response so the operator sees mostly command output. Repository structure is minimal: README.md documents the target as BIRT Viewer on Windows and notes testing against BIRT 4.8.0, while the Python script is the sole operational entry point. There is no framework integration, no modularization, and no payload customization beyond the operator-supplied command. Overall, this is an operational web RCE exploit that drops a persistent JSP webshell and provides arbitrary command execution against vulnerable Eclipse BIRT deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.