TIBCO Vulnerabilities and Affected Products
Vulnerabilities associated with JasperReports.
Products
Clear product- JasperReports2 vulnerabilities
- jasperreports_server2 vulnerabilities
- Spotfire Analyst2 vulnerabilities
- Spotfire Connectors2 vulnerabilities
- Spotfire Deployment Kit2 vulnerabilities
- Spotfire Desktop2 vulnerabilities
- Spotfire Desktop Developer Edition2 vulnerabilities
- Spotfire Desktop Language Packs2 vulnerabilities
- ActiveMatrix BusinessWorks1 vulnerability
- EBX1 vulnerability
- Enterprise Administrator1 vulnerability
- ftl1 vulnerability
- Hawk1 vulnerability
- JasperReports Server1 vulnerability
- Silver Fabric Enabler for Spotfire Web Player1 vulnerability
- Spotfire Analytics Platform for AWS Marketplace1 vulnerability
- Spotfire Automation Services 61 vulnerability
- Spotfire Client1 vulnerability
- Spotfire Professional1 vulnerability
- Spotfire Web Player1 vulnerability
- Spotfire Web Player Client1 vulnerability
- spotfire_analyst1 vulnerability
- spotfire_analytics_platform_for_aws1 vulnerability
- spotfire_server1 vulnerability
- TIBCO BPM Enterprise1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-18809MEDIUM | TIBCO JasperReports Library Directory Traversal VulnerabilityThe default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to … | CVSS6.5v3.1 | EPSS79.1% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-5430HIGH | TIBCO JasperReports Server Information Disclosure VulnerabilityThe Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: ve… | CVSS8.8v3.1 | EPSS48.8% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |