CVE-2018-5430
KEV PoC ×2moderatePath Traversal in TIBCO JasperReports Server Exposes Config Files
CISA: TIBCO JasperReports Server Information Disclosure Vulnerability
TIBCO JasperReports Server contains a path traversal flaw (CWE-22) that allows any authenticated user read-only access to the contents of the web application, including key configuration files. Because only a valid user account is required rather than administrative rights, any low-privileged user can send crafted traversal requests and read sensitive files within the application's web root. An attacker gains visibility into configuration data, which commonly includes application settings and embedded credentials that could support further compromise of the reporting platform or its connected databases. Any organization running an affected JasperReports Server deployment, particularly internet-facing instances, is exposed. The flaw is being actively exploited in the wild, as shown by its addition to CISA's Known Exploited Vulnerabilities catalog on 2022-12-29, EPSS assigns it roughly a 50% chance of exploitation within 30 days (99th percentile), no public PoC is known, and any association with ransomware is unknown.
What to do: Apply the vendor fix per TIBCO's security advisory and upgrade all JasperReports Server instances to a patched release, as required by CISA's KEV listing. Until patched, restrict which accounts can authenticate, limit internet exposure of the JasperReports console, and check access logs for unexpected reads of configuration files. If configuration files containing credentials may have been accessed, rotate those credentials.
| TIBCO JasperReports Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
- Affected
- TIBCO JasperReports
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- tibco
- Products
- jasperreports server, jaspersoft, jaspersoft reporting and analytics
- Weakness
- CWE-22, CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H