A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent remote access to all the contents of the web application, including key configuration files. Affected releases are TIBCO JasperReports Server 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NTibco Jasperreports Server
APPTibco6.4.0Tibco Jaspersoft
APPTibco6.4.0Tibco Jaspersoft Reporting And Analytics
APPTibco6.4.0
Related vulnerabilities
RCE w komponencie JNDI Data Sources TIBCO JasperReports Server
Stored XSS w komponencie Dashboard TIBCO JasperReports Server
TIBCO JasperReports Server — kradzież haseł FTP przez komponent Scheduler Connection
Auth Bypass w TIBCO JasperReports Server — nieautoryzowany dostęp superużytkownika
Pominięcie autoryzacji w REST API TIBCO JasperReports Server