The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HTibco Jasperreports Server
APPTibco6.4.06.4.16.4.26.4.37.1.0≤ 6.4.3≤ 7.1.0Tibco Jaspersoft
APPTibco≤ 7.1.0Tibco Jaspersoft Reporting And Analytics
APPTibco≤ 7.1.0
Related vulnerabilities
Stored XSS w komponencie Dashboard TIBCO JasperReports Server
RCE w komponencie JNDI Data Sources TIBCO JasperReports Server
TIBCO JasperReports Server — kradzież haseł FTP przez komponent Scheduler Connection
Auth Bypass w TIBCO JasperReports Server — nieautoryzowany dostęp superużytkownika
TIBCO JasperReports Server — nieautoryzowany dostęp do plików konfiguracyjnych