PT-2019-19289 · Tibco · Tibco Jasperreports Server For Activematrix Bpm+1

Publicado

2019-03-07

·

Atualizado

2022-01-01

·

CVE-2019-8986

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TIBCO JasperReports Server versions up to and including 6.4.3 TIBCO JasperReports Server for ActiveMatrix BPM versions up to and including 6.4.3
Description The issue allows a malicious authenticated user to copy text files from the host operating system through the SOAP API component.
Recommendations For TIBCO JasperReports Server versions up to and including 6.4.3, update to a version later than 6.4.3 to resolve the issue. For TIBCO JasperReports Server for ActiveMatrix BPM versions up to and including 6.4.3, update to a version later than 6.4.3 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-8986

Produtos afetados

Tibco Jasperreports Server
Tibco Jasperreports Server For Activematrix Bpm