Junglewise Threat Intelligence

CVE-2018-5430: TIBCO JasperReports Server Information Disclosure Vulnerability

CVE-2018-5430 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-12-29

Executive brief

The Spring web flows in TIBCO JasperReports Server contain a path traversal vulnerability (CWE-22). This allows authenticated users to gain read-only access to sensitive web application contents and key configuration files.

Affected products

  • TIBCO JasperReports Server up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2
  • TIBCO JasperReports Server Community Edition up to and including 6.4.2
  • TIBCO JasperReports Server for ActiveMatrix BPM up to and including 6.4.2
  • TIBCO Jaspersoft for AWS with Multi-Tenancy up to and including 6.4.2
  • TIBCO Jaspersoft Reporting and Analytics for AWS up to and including 6.4.2

Timeline

  • 2018-04-17: advisory: Original TIBCO security advisory date
  • 2022-12-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats