ZeroHour

CVE-2018-18809

KEV PoC ×2large

Directory Traversal in TIBCO JasperReports Library and Server

CISA: TIBCO JasperReports Library Directory Traversal Vulnerability

CVSS 3.1
6.5 medium
EPSS
79%p100
Published
()
KEV added
AI analysis

CVE-2018-18809 is a directory-traversal flaw (CWE-22) in the default server implementation of TIBCO JasperReports Library and TIBCO JasperReports Server, including the Community Editions and the bundled ActiveMatrix BPM and Jaspersoft AWS variants. A low-privileged web server user can send crafted requests containing traversal sequences to the report server's web interface, causing the server to read files outside the intended directory. The impact is limited to confidentiality — an attacker gains access to the contents of the host system (CVSS C:H, with no integrity or availability impact) — but reading arbitrary files can expose configuration files, credentials, and other sensitive data. All listed 6.x and 7.x releases of the affected products are vulnerable, so any organization running JasperReports Server or embedding the JasperReports library is in scope. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-12-29, citing active exploitation, and EPSS estimates a 79.1% probability of exploitation within 30 days, so defenders should treat it as exploited in the wild.

What to do: Upgrade affected JasperReports Library and JasperReports Server deployments to the fixed releases specified in TIBCO's security advisory for CVE-2018-18809, and remember to patch embedded copies shipped with ActiveMatrix BPM and the Jaspersoft AWS offerings. Prioritize internet-facing JasperReports Server instances, since CISA lists this as actively exploited, and restrict web access to report servers where patching is delayed. Review web server and application logs for path-traversal patterns indicating probing or successful file reads.

Affected
TIBCO JasperReports Libraryup to and including 6.3.4, 6.4.1, 6.4.2, 6.4.21, 7.1.0, and 7.2.0
TIBCO JasperReports Library Community Editionup to and including 6.7.0
TIBCO JasperReports Library for ActiveMatrix BPMup to and including 6.4.21
TIBCO JasperReports Serverup to and including 6.3.4, 6.4.0, 6.4.1, 6.4.2, 6.4.3, and 7.1.0
TIBCO JasperReports Server Community Editionup to and including 6.4.3 and 7.1.0
TIBCO JasperReports Server for ActiveMatrix BPMup to and including 6.4.3
TIBCO Jaspersoft for AWS with Multi-Tenancyup to and including 7.1.0
TIBCO Jaspersoft Reporting and Analytics for AWSup to and including 7.1.0
Estimated exposure
large≈tens of thousands of deployments worldwide (order of 10k–100k exposed or embedded instances) — JasperReports/Jaspersoft is one of the most widely embedded open-source reporting platforms (historically marketed with a very large production-deployment and OEM-embedding base), and public internet scans routinely surface thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

CISA Known Exploited Vulnerability
Affected
TIBCO JasperReports
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
tibco
Products
jasperreports library, jasperreports server, jaspersoft, jaspersoft reporting and analytics
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news