peter bassill · operator
$ cve CVE-2018-18809 JSON

CVE-2018-18809 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 79.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-01-19.

Description

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS79.06% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2023-01-19
Public exploitnone known
Published2019-03-07
Last modified2026-06-17

CISA KEV

NameTIBCO JasperReports Library Directory Traversal Vulnerability
Added2022-12-29
Due2023-01-19
Vendor / productTIBCO / JasperReports
Ransomware usenone reported

Affected (4)

VendorProduct
tibcojasperreports library
tibcojasperreports server
tibcojaspersoft
tibcojaspersoft reporting and analytics

References

→ the Explorer  ·  watch your stack  ·  NVD