Vulnerable and Outdated Components in SSRS

Akshayaa Kalyanavenkatesh 40 Reputation points
2025-04-22T06:41:49.02+00:00

When we performed Burp Suite Professional scan for SSRS module, we have come across different vulnerable and outdated components which are listed below :

jquery version 3.1.1

angularjs version 1.5.7

moment.js version 2.14.1

bootstrap version 3.3.5

can you please help us on this

SQL Server Reporting Services
SQL Server Reporting Services
A SQL Server technology that supports the creation, management, and delivery of both traditional, paper-oriented reports and interactive, web-based reports.
3,042 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Azar 28,000 Reputation points MVP
    2025-04-22T17:53:40.9266667+00:00

    Hi there Akshayaa Kalyanavenkatesh

    Thanks for using QandA platform

    The libs you listyed arare indeed outdated and might contain known vulnerabilities.

    Unfortunately, SSRS uses these libraries as part of its built-in UI, and Microsoft doesn’t provide an official way to update or patch them manually without breaking the SSRS functionality or supportability.

    try to Host custom reports in an external app (e.g., ASP.NET with up-to-date libs) and connect to SSRS via API.

    Use (CSP) headers or Web Application Firewall (WAF) to mitigate risks.

    Restrict access to the SSRS web portal to trusted users/networks only.

    If this helps kindly accept the answer thanks much.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.