Back to overview

CVE-2018-18809

CRITICAL KEV CISA Exploitation: ACTIVE
9.9
CVSS 3.0
Description
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Metadata

CVE ID
CVE-2018-18809
State
PUBLISHED
Assigner
tibco
Reserved
2018-10-29 00:00 UTC
Published
2019-03-07 22:00 UTC
Last updated
2025-10-21 23:45 UTC
Primary CWE
CWE-22
CWE-22 Improper Limitation of a Pathname to a Restricted Dir…
Vendor / Product
TIBCO Software Inc. / TIBCO JasperReports Library
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
TIBCO JasperReports Library Directory Traversal Vulnerability
Vendor
TIBCO
Product
JasperReports
Added to KEV
2022-12-29
Due date
2023-01-19
Ransomware
Not known
Required action
Apply updates per vendor instructions.
CISA description
TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
Affected products (8)
VendorProductPlatformVersions
TIBCO Software Inc. TIBCO JasperReports Library unspecified ≤ 6.3.4, 6.4.1, 6.4.2, 6.4.21 …
TIBCO Software Inc. TIBCO JasperReports Library Community Edition unspecified ≤ 6.7.0
TIBCO Software Inc. TIBCO JasperReports Library for ActiveMatrix BPM unspecified ≤ 6.4.21
TIBCO Software Inc. TIBCO JasperReports Server unspecified ≤ 6.3.4, 6.4.0, 6.4.1, 6.4.2 …
TIBCO Software Inc. TIBCO JasperReports Server Community Edition unspecified ≤ 6.4.3, 7.1.0
TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM unspecified ≤ 6.4.3
TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy unspecified ≤ 7.1.0
TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS unspecified ≤ 7.1.0
Weakness (CWE)
CWESourceDescription
cna The impact of this vulnerability includes the theoretical possibility that a web server using the provided DefaultWebResourceHandler could expose details of the host system. The disclosed data could include credentials to access other systems.
CWE-22 adp CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview