ZeroHour

CVE-2018-5430

KEV PoC ×2moderate

Path Traversal in TIBCO JasperReports Server Exposes Config Files

CISA: TIBCO JasperReports Server Information Disclosure Vulnerability

CVSS 3.1
8.8 high
EPSS
50%p99
Published
()
KEV added
AI analysis

TIBCO JasperReports Server contains a path traversal flaw (CWE-22) that allows any authenticated user read-only access to the contents of the web application, including key configuration files. Because only a valid user account is required rather than administrative rights, any low-privileged user can send crafted traversal requests and read sensitive files within the application's web root. An attacker gains visibility into configuration data, which commonly includes application settings and embedded credentials that could support further compromise of the reporting platform or its connected databases. Any organization running an affected JasperReports Server deployment, particularly internet-facing instances, is exposed. The flaw is being actively exploited in the wild, as shown by its addition to CISA's Known Exploited Vulnerabilities catalog on 2022-12-29, EPSS assigns it roughly a 50% chance of exploitation within 30 days (99th percentile), no public PoC is known, and any association with ransomware is unknown.

What to do: Apply the vendor fix per TIBCO's security advisory and upgrade all JasperReports Server instances to a patched release, as required by CISA's KEV listing. Until patched, restrict which accounts can authenticate, limit internet exposure of the JasperReports console, and check access logs for unexpected reads of configuration files. If configuration files containing credentials may have been accessed, rotate those credentials.

Affected
TIBCO JasperReports Server
Estimated exposure
moderateon the order of thousands of deployments, including low thousands of internet-exposed instances; precise counts unknown — JasperReports Server is a widely deployed enterprise BI/reporting platform typically installed at enterprise and product-bundled sites, with public internet scans surfacing only low thousands of exposed instances, while exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

CISA Known Exploited Vulnerability
Affected
TIBCO JasperReports
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
tibco
Products
jasperreports server, jaspersoft, jaspersoft reporting and analytics
Weakness
CWE-22, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news