Executive brief
TIBCO JasperReports Library and Server products contain a directory traversal vulnerability. An authenticated attacker can exploit this to access sensitive files on the host system, potentially leading to full system compromise.
Affected products
- TIBCO Software Inc. JasperReports Library up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0
- TIBCO Software Inc. JasperReports Library Community Edition up to and including 6.7.0
- TIBCO Software Inc. JasperReports Library for ActiveMatrix BPM up to and including 6.4.21
- TIBCO Software Inc. JasperReports Server up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0
- TIBCO Software Inc. JasperReports Server Community Edition up to and including 6.4.3; 7.1.0
- TIBCO Software Inc. JasperReports Server for ActiveMatrix BPM up to and including 6.4.3
- TIBCO Software Inc. Jaspersoft for AWS with Multi-Tenancy up to and including 7.1.0
- TIBCO Software Inc. Jaspersoft Reporting and Analytics for AWS up to and including 7.1.0
Timeline
- 2019-03-06: advisory: Initial vendor advisory published by TIBCO.
- 2022-12-29: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2022-12-29: disclosed: NVD publication date.