多款TIBCO Software产品中的存储库组件存在跨站脚本漏洞。远程攻击者可利用该漏洞获取Web接口(受影响组件)的全部访问权限。以下产品和版本受到影响:TIBCO JasperReports Server 6.3.4版本,6.4.0版本,6.4.1版本,6.4.2版本,6.4.3版本,7.1.0版本;TIBCO JasperReports Server(社区版)7.1.0及之前版本;适用于ActiveMatrix BPM的TIBCO JasperReports Server 6.4.3及之前版本;T
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TIBCO Software Inc. | TIBCO JasperReports Server | unspecified ~ 6.3.4 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server Community Edition | unspecified ~ 7.1.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server for ActiveMatrix BPM | unspecified ~ 6.4.3 | - |
|
| TIBCO Software Inc. | TIBCO Jaspersoft for AWS with Multi-Tenancy | unspecified ~ 7.1.0 | - |
|
| TIBCO Software Inc. | TIBCO Jaspersoft Reporting and Analytics for AWS | unspecified ~ 7.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-18808 | TIBCO JasperReports Server Privilege Escalation Via Race Condition | |
| CVE-2018-18809 | TIBCO JasperReports Library Directory Traversal Vulnerability | |
| CVE-2018-18815 | TIBCO JasperReports Server User Information Disclosure | |
| CVE-2019-8986 | TIBCO JasperReports Server XML Entity Expansion Vulnerability |
No comments yet