CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2018-18815

CVSS 10.0v3.0pub. 2019-03-07upd. 2024-11-21

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Tibco Jasperreports Server

    APP
    Tibco
    6.4.06.4.16.4.26.4.37.1.0≤ 6.4.3≤ 7.1.0
  • Tibco Jaspersoft

    APP
    Tibco
    ≤ 7.1.0
  • Tibco Jaspersoft Reporting And Analytics

    APP
    Tibco
    ≤ 7.1.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2022-41563CRITICAL9.0PL ✓same product

Stored XSS w komponencie Dashboard TIBCO JasperReports Server

CVE-2022-41561CRITICAL9.1PL ✓same product

RCE w komponencie JNDI Data Sources TIBCO JasperReports Server

CVE-2021-35495CRITICAL9.0PL ✓same product

TIBCO JasperReports Server — kradzież haseł FTP przez komponent Scheduler Connection

CVE-2020-9409CRITICAL9.8PL ✓same product

Auth Bypass w TIBCO JasperReports Server — nieautoryzowany dostęp superużytkownika

CVE-2017-5533CRITICAL9.3PL ✓same product

TIBCO JasperReports Server — nieautoryzowany dostęp do plików konfiguracyjnych