{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-23T12:43:08.151","vulnerabilities":[{"cve":{"id":"CVE-2019-11776","sourceIdentifier":"emo@eclipse.org","published":"2019-08-09T19:15:11.063","lastModified":"2026-06-17T02:13:37.320","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context."},{"lang":"es","value":"En BIRT de Eclipse versiones 1.0 hasta 4.7, el Visor de Reportes permite un ataque de tipo XSS reflejado en el parámetro URL. El atacante puede ejecutar la carga útil en el contexto del navegador de la víctima."}],"affected":[{"source":"emo@eclipse.org","affectedData":[{"vendor":"The Eclipse Foundation","product":"Eclipse BIRT","versions":[{"version":"1.0 to 4.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"emo@eclipse.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:eclipse:business_intelligence_and_reporting_tools:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0","versionEndIncluding":"4.7.0","matchCriteriaId":"1CFCA522-FCA5-4EA0-8357-7E89E514C4B6"}]}]}],"references":[{"url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=546816","source":"emo@eclipse.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=546816","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}}]}