CVE-2018-18815
CRITICAL
10.0
CVSS 3.0
Description
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (5)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| TIBCO Software Inc. | TIBCO JasperReports Server | — | 6.4.0, 6.4.1, 6.4.2, 6.4.3 … |
| TIBCO Software Inc. | TIBCO JasperReports Server Community Edition | — | unspecified ≤ 7.1.0 |
| TIBCO Software Inc. | TIBCO JasperReports Server for ActiveMatrix BPM | — | unspecified ≤ 6.4.3 |
| TIBCO Software Inc. | TIBCO Jaspersoft for AWS with Multi-Tenancy | — | unspecified ≤ 7.1.0 |
| TIBCO Software Inc. | TIBCO Jaspersoft Reporting and Analytics for AWS | — | unspecified ≤ 7.1.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | The impact of this vulnerability includes the theoretical possibility of unauthenticated read access to the contents of the host system, when combined with the vulnerability identified by CVE-2018-18809. |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (5)
- https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-server-2018-18815
- http://www.tibco.com/services/support/advisories
- https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809
- 107346 http://www.securityfocus.com/bid/107346
- https://www.zerodayinitiative.com/advisories/ZDI-19-305/