Executive brief
The Spring web flows in TIBCO JasperReports Server contain a path traversal vulnerability (CWE-22). This allows authenticated users to gain read-only access to sensitive web application contents and key configuration files.
Affected products
- TIBCO JasperReports Server up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2
- TIBCO JasperReports Server Community Edition up to and including 6.4.2
- TIBCO JasperReports Server for ActiveMatrix BPM up to and including 6.4.2
- TIBCO Jaspersoft for AWS with Multi-Tenancy up to and including 6.4.2
- TIBCO Jaspersoft Reporting and Analytics for AWS up to and including 6.4.2
Timeline
- 2018-04-17: advisory: Original TIBCO security advisory date
- 2022-12-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog