Eclipse BIRT versions 2.2.1 and below suffer from a cross site scripting vulnerability.
76aaa9ef642b127b8f3769f2e8f89c652d6655bb52ea7728108117500596d207
Pentaho version 1.7.0.1062 and below suffer from cross site scripting and disclosure vulnerabilities.
49597cb26cd53ef0182ae67b4e95514579433cf0c35d17be9d1532ca908e5593
WebWeaver version 1.06 and below allows for anonymous surfing of the server if the Host field is set excessively long. It is also susceptible to various denial of services attacks.
d379db7c0aee30b485cfe256c1ea095e1ecc0ca84aa0b246acdf7e56cbf677dc