CVE-2018-18809
KEV PoC ×2largeDirectory Traversal in TIBCO JasperReports Library and Server
CISA: TIBCO JasperReports Library Directory Traversal Vulnerability
CVE-2018-18809 is a directory-traversal flaw (CWE-22) in the default server implementation of TIBCO JasperReports Library and TIBCO JasperReports Server, including the Community Editions and the bundled ActiveMatrix BPM and Jaspersoft AWS variants. A low-privileged web server user can send crafted requests containing traversal sequences to the report server's web interface, causing the server to read files outside the intended directory. The impact is limited to confidentiality — an attacker gains access to the contents of the host system (CVSS C:H, with no integrity or availability impact) — but reading arbitrary files can expose configuration files, credentials, and other sensitive data. All listed 6.x and 7.x releases of the affected products are vulnerable, so any organization running JasperReports Server or embedding the JasperReports library is in scope. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-12-29, citing active exploitation, and EPSS estimates a 79.1% probability of exploitation within 30 days, so defenders should treat it as exploited in the wild.
What to do: Upgrade affected JasperReports Library and JasperReports Server deployments to the fixed releases specified in TIBCO's security advisory for CVE-2018-18809, and remember to patch embedded copies shipped with ActiveMatrix BPM and the Jaspersoft AWS offerings. Prioritize internet-facing JasperReports Server instances, since CISA lists this as actively exploited, and restrict web access to report servers where patching is delayed. Review web server and application logs for path-traversal patterns indicating probing or successful file reads.
| TIBCO JasperReports Library | up to and including 6.3.4, 6.4.1, 6.4.2, 6.4.21, 7.1.0, and 7.2.0 |
| TIBCO JasperReports Library Community Edition | up to and including 6.7.0 |
| TIBCO JasperReports Library for ActiveMatrix BPM | up to and including 6.4.21 |
| TIBCO JasperReports Server | up to and including 6.3.4, 6.4.0, 6.4.1, 6.4.2, 6.4.3, and 7.1.0 |
| TIBCO JasperReports Server Community Edition | up to and including 6.4.3 and 7.1.0 |
| TIBCO JasperReports Server for ActiveMatrix BPM | up to and including 6.4.3 |
| TIBCO Jaspersoft for AWS with Multi-Tenancy | up to and including 7.1.0 |
| TIBCO Jaspersoft Reporting and Analytics for AWS | up to and including 7.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
- Affected
- TIBCO JasperReports
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- tibco
- Products
- jasperreports library, jasperreports server, jaspersoft, jaspersoft reporting and analytics
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N