CVE-2017-5529

MEDIUM

Tibco Jasperreports Library Community Edition - Information Disclosure

Title source: rule

Description

JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO JasperReports Professional (versions 6.2.1 and below, and 6.3.0), TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.3.0 and below), TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.3.0 and below), and TIBCO Jaspersoft Studio for ActiveMatrix BPM (versions 6.2.0 and below).

Scores

CVSS v3 4.1
EPSS 0.0031
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (26)
tibco/jasperreports_library_community_edition < 6.4.0
tibco/jasperreports_library_for_activematrix_bpm < 6.2.0
tibco/jasperreports_professional < 6.2.1
tibco/jasperreports_professional
tibco/jasperreports_server < 6.1.1
tibco/jasperreports_server
tibco/jasperreports_server
tibco/jasperreports_server
tibco/jasperreports_server_community_edition < 6.3.0
tibco/jasperreports_server_for_activematrix_bpm < 6.2.0
... and 16 more
Published Jun 29, 2017
Tracked Since Feb 18, 2026