Tibco Software TIBCO Software JasperReports Server是美国TIBCO Software(Tibco Software)公司的一款可嵌入的报告服务器,它提供可以嵌入到Web或移动设备中的报告和分析功能。 TIBCO Software Inc.的多款产品存在竞争条件问题漏洞,攻击者可利用该漏洞通过REST API获得对受影响系统上其他用户创建的临时对象的读取访问权。受影响的版本包括TIBCO Software Inc.的TIBCO JasperReports服务
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TIBCO Software Inc. | TIBCO JasperReports Server | unspecified ~ 7.2.1 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server | 7.5.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server | 7.8.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server | 7.9.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server - Community Edition | unspecified ~ 7.8.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server - Developer Edition | unspecified ~ 7.9.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server for AWS Marketplace | unspecified ~ 7.9.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server for ActiveMatrix BPM | unspecified ~ 7.9.0 | - |
|
| TIBCO Software Inc. | TIBCO JasperReports Server for Microsoft Azure | 7.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-35495 | 9.0 CRITICAL | TIBCO JasperReports FTP Password exposed |
| CVE-2021-35496 | 7.5 HIGH | TIBCO JasperReports XML Eternal Entity (XXE) vulnerability |
No comments yet