CVE-2020-9409
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.5% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-276 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-05-20 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| oracle | retail order broker |
| tibco | jasperreports server |
References
→ the Explorer · watch your stack · NVD