Junglewise Threat Intelligence

CVE-2018-18809: TIBCO JasperReports Library Directory Traversal Vulnerability

CVE-2018-18809 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2022-12-29

Executive brief

TIBCO JasperReports Library and Server products contain a directory traversal vulnerability. An authenticated attacker can exploit this to access sensitive files on the host system, potentially leading to full system compromise.

Affected products

  • TIBCO Software Inc. JasperReports Library up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0
  • TIBCO Software Inc. JasperReports Library Community Edition up to and including 6.7.0
  • TIBCO Software Inc. JasperReports Library for ActiveMatrix BPM up to and including 6.4.21
  • TIBCO Software Inc. JasperReports Server up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0
  • TIBCO Software Inc. JasperReports Server Community Edition up to and including 6.4.3; 7.1.0
  • TIBCO Software Inc. JasperReports Server for ActiveMatrix BPM up to and including 6.4.3
  • TIBCO Software Inc. Jaspersoft for AWS with Multi-Tenancy up to and including 7.1.0
  • TIBCO Software Inc. Jaspersoft Reporting and Analytics for AWS up to and including 7.1.0

Timeline

  • 2019-03-06: advisory: Initial vendor advisory published by TIBCO.
  • 2022-12-29: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2022-12-29: disclosed: NVD publication date.

Related threats