CISA adds JasperReports bugs to its Known Exploited Vulnerabilities Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-18809 | Directory Traversal in TIBCO JasperReports Library and Server CVE-2018-18809 is a directory-traversal flaw (CWE-22) in the default server implementation of TIBCO JasperReports Library and TIBCO JasperReports Server, including the Community Editions and the bundled ActiveMatrix BPM and Jaspersoft AWS variants. A low-privileged web server user can send crafted requests containing traversal sequences to the report server's web interface, causing the server to read files outside the intended directory. The impact is limited to confidentiality — an attacker gains access to the contents of the host system (CVSS C:H, with no integrity or availability impact) — but reading arbitrary files can expose configuration files, credentials, and other sensitive data. All listed 6.x and 7.x releases of the affected products are vulnerable, so any organization running JasperReports Server or embedding the JasperReports library is in scope. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-12-29, citing active exploitation, and EPSS estimates a 79.1% probability of exploitation within 30 days, so defenders should treat it as exploited in the wild. Do: Upgrade affected JasperReports Library and JasperReports Server deployments to the fixed releases specified in TIBCO's security advisory for CVE-2018-18809, and remember to patch embedded copies shipped with ActiveMatrix BPM and the Jaspersoft AWS offerings. Prioritize internet-facing JasperReports Server instances, since CISA lists this as actively exploited, and restrict web access to report servers where patching is delayed. Review web server and application logs for path-traversal patterns indicating probing or successful file reads. | 6.5 | 79% | KEV PoC ×2 |
| large≈tens of thousands of deployments worldwide (order of 10k–100k exposed or embedded instances) | |
| CVE-2018-5430 | Path Traversal in TIBCO JasperReports Server Exposes Config Files TIBCO JasperReports Server contains a path traversal flaw (CWE-22) that allows any authenticated user read-only access to the contents of the web application, including key configuration files. Because only a valid user account is required rather than administrative rights, any low-privileged user can send crafted traversal requests and read sensitive files within the application's web root. An attacker gains visibility into configuration data, which commonly includes application settings and embedded credentials that could support further compromise of the reporting platform or its connected databases. Any organization running an affected JasperReports Server deployment, particularly internet-facing instances, is exposed. The flaw is being actively exploited in the wild, as shown by its addition to CISA's Known Exploited Vulnerabilities catalog on 2022-12-29, EPSS assigns it roughly a 50% chance of exploitation within 30 days (99th percentile), no public PoC is known, and any association with ransomware is unknown. Do: Apply the vendor fix per TIBCO's security advisory and upgrade all JasperReports Server instances to a patched release, as required by CISA's KEV listing. Until patched, restrict which accounts can authenticate, limit internet exposure of the JasperReports console, and check access logs for unexpected reads of configuration files. If configuration files containing credentials may have been accessed, rotate those credentials. | 8.8 | 50% | KEV PoC ×2 |
| moderateon the order of thousands of deployments, including low thousands of internet-exposed instances; precise counts unknown |
Full article211 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 30, 2022

US CISA added TIBCO Software’s JasperReports vulnerabilities to its Known Exploited Vulnerabilities Catalog.
US CISA added TIBCO Software’s JasperReports vulnerabilities, tracked as CVE-2018-5430 (CVSS score: 7.7) and CVE-2018-18809 (CVSS score: 9.9), to its Known Exploited Vulnerabilities (KEV) catalog,.
TIBCO JasperReports is an open-source Java reporting tool for creating and managing reports and dashboards.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
Below are the vulnerabilities added to the catalog:
- CVE-2018-5430 – TIBCO JasperReports Server contains a vulnerability that may allow any authenticated user read-only access to the contents of the web application, including key configuration files.
- CVE-2018-18809 – TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
US Federal agencies have to address these vulnerabilities in their systems by January 19, 2023.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, CISA)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/140131/security/known-exploited-vulnerabilities-catalog-jasperreports.html