peter bassill · operator
$ cve CVE-2018-5430 JSON

CVE-2018-5430 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 49% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2023-01-19.

Description

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS48.99% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2023-01-19
Public exploityes
Published2018-04-17
Last modified2026-06-17

CISA KEV

NameTIBCO JasperReports Server Information Disclosure Vulnerability
Added2022-12-29
Due2023-01-19
Vendor / productTIBCO / JasperReports
Ransomware usenone reported

Affected (3)

VendorProduct
tibcojasperreports server
tibcojaspersoft
tibcojaspersoft reporting and analytics

Public exploits

SourceTitleDate
exploit-dbJasperReports - (Authenticated) File Read2018-05-03

References

→ the Explorer  ·  watch your stack  ·  NVD