PT-2019-6316 · Tibco Software · Tibco Jasperreports Library For Activematrix Bpm+7

Elar Lang

·

Published

2019-03-07

·

Updated

2025-02-12

·

CVE-2018-18809

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIBCO JasperReports Library versions up to and including 7.2.0 TIBCO JasperReports Library Community Edition versions up to and including 6.7.0 TIBCO JasperReports Library for ActiveMatrix BPM versions up to and including 6.4.21 TIBCO JasperReports Server versions up to and including 7.1.0 TIBCO JasperReports Server Community Edition versions up to and including 7.1.0 TIBCO JasperReports Server for ActiveMatrix BPM versions up to and including 6.4.3 TIBCO Jaspersoft for AWS with Multi-Tenancy versions up to and including 7.1.0 TIBCO Jaspersoft Reporting and Analytics for AWS versions up to and including 7.1.0
Description The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. This issue is related to incorrect restriction of a pathname to a directory with limited access. Exploitation of this vulnerability may allow a remote attacker to disclose protected information.
Recommendations For TIBCO JasperReports Library versions up to and including 7.2.0, update to a version that includes a fix for this vulnerability. For TIBCO JasperReports Library Community Edition versions up to and including 6.7.0, update to a version that includes a fix for this vulnerability. For TIBCO JasperReports Library for ActiveMatrix BPM versions up to and including 6.4.21, update to a version that includes a fix for this vulnerability. For TIBCO JasperReports Server versions up to and including 7.1.0, update to a version that includes a fix for this vulnerability. For TIBCO JasperReports Server Community Edition versions up to and including 7.1.0, update to a version that includes a fix for this vulnerability. For TIBCO JasperReports Server for ActiveMatrix BPM versions up to and including 6.4.3, update to a version that includes a fix for this vulnerability. For TIBCO Jaspersoft for AWS with Multi-Tenancy versions up to and including 7.1.0, update to a version that includes a fix for this vulnerability. For TIBCO Jaspersoft Reporting and Analytics for AWS versions up to and including 7.1.0, update to a version that includes a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive directories and files on the host system to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-00914
CVE-2018-18809

Affected Products

Tibco Jasperreports Library
Jasperreports Library Community Edition
Tibco Jasperreports Library For Activematrix Bpm
Tibco Jasperreports Server
Tibco Jasperreports Server Community Edition
Tibco Jasperreports Server For Activematrix Bpm
Tibco Jaspersoft Reporting/Analytics For Aws
Tibco Jaspersoft For Aws With Multi-Tenancy