CISA Warns of Active exploitation of JasperReports Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-18809 | Directory Traversal in TIBCO JasperReports Library and Server CVE-2018-18809 is a directory-traversal flaw (CWE-22) in the default server implementation of TIBCO JasperReports Library and TIBCO JasperReports Server, including the Community Editions and the bundled ActiveMatrix BPM and Jaspersoft AWS variants. A low-privileged web server user can send crafted requests containing traversal sequences to the report server's web interface, causing the server to read files outside the intended directory. The impact is limited to confidentiality — an attacker gains access to the contents of the host system (CVSS C:H, with no integrity or availability impact) — but reading arbitrary files can expose configuration files, credentials, and other sensitive data. All listed 6.x and 7.x releases of the affected products are vulnerable, so any organization running JasperReports Server or embedding the JasperReports library is in scope. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-12-29, citing active exploitation, and EPSS estimates a 79.1% probability of exploitation within 30 days, so defenders should treat it as exploited in the wild. Do: Upgrade affected JasperReports Library and JasperReports Server deployments to the fixed releases specified in TIBCO's security advisory for CVE-2018-18809, and remember to patch embedded copies shipped with ActiveMatrix BPM and the Jaspersoft AWS offerings. Prioritize internet-facing JasperReports Server instances, since CISA lists this as actively exploited, and restrict web access to report servers where patching is delayed. Review web server and application logs for path-traversal patterns indicating probing or successful file reads. | 6.5 | 79% | KEV PoC ×2 |
| large≈tens of thousands of deployments worldwide (order of 10k–100k exposed or embedded instances) | |
| CVE-2018-5430 | Path Traversal in TIBCO JasperReports Server Exposes Config Files TIBCO JasperReports Server contains a path traversal flaw (CWE-22) that allows any authenticated user read-only access to the contents of the web application, including key configuration files. Because only a valid user account is required rather than administrative rights, any low-privileged user can send crafted traversal requests and read sensitive files within the application's web root. An attacker gains visibility into configuration data, which commonly includes application settings and embedded credentials that could support further compromise of the reporting platform or its connected databases. Any organization running an affected JasperReports Server deployment, particularly internet-facing instances, is exposed. The flaw is being actively exploited in the wild, as shown by its addition to CISA's Known Exploited Vulnerabilities catalog on 2022-12-29, EPSS assigns it roughly a 50% chance of exploitation within 30 days (99th percentile), no public PoC is known, and any association with ransomware is unknown. Do: Apply the vendor fix per TIBCO's security advisory and upgrade all JasperReports Server instances to a patched release, as required by CISA's KEV listing. Until patched, restrict which accounts can authenticate, limit internet exposure of the JasperReports console, and check access logs for unexpected reads of configuration files. If configuration files containing credentials may have been accessed, rotate those credentials. | 8.8 | 50% | KEV PoC ×2 |
| moderateon the order of thousands of deployments, including low thousands of internet-exposed instances; precise counts unknown |
Full article254 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 30, 2022Patch Management
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two years-old security flaws impacting TIBCO Software's JasperReports product to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The flaws, tracked as CVE-2018-5430 (CVSS score: 7.7) and CVE-2018-18809 (CVSS score: 9.9), were addressed by TIBCO in April 2018 and March 2019, respectively.
TIBCO JasperReports is a Java-based reporting and data analytics platform for creating, distributing, and managing reports and dashboards.
The first of the two issues, CVE-2018-5430, relates to an information disclosure bug in the server component that could enable an authenticated user to gain read-only access to arbitrary files, including key configurations.
"The impact includes the possible read-only access by authenticated users to web application configuration files that contain the credentials used by the server," TIBCO noted at the time. "Those credentials could then be used to affect external systems accessed by the JasperReports Server."
CVE-2018-18809, on the other hand, is a directory traversal vulnerability in the JasperReports Library that could permit web server users to access sensitive files on the host, potentially making it possible for an attacker to steal credentials and break into other systems.
CISA did not disclose any additional specifics about how the vulnerabilities are being weaponized in real-world attacks. Federal agencies in the U.S. are required to patch their systems by January 19, 2023.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/12/cisa-warns-of-active-exploitation-of.html