CVE-2018-5431
TIBCO JasperReports Server Cross Site Scripting Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
El componente domain designer de TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy y TIBCO Jaspersoft Reporting and Analytics for AWS, de TIBCO Software Inc., contiene una vulnerabilidad que podrÃa permitir, en el contexto de una configuración de permisos que no sea por defecto, ataques de Cross-Site Scripting (XSS) persistente. Las versiones afectadas incluyen TIBCO JasperReports Server: versiones hasta e incluyendo la 6.2.4, 6.3.0, 6.3.2, 6.3.3, 6.4.0 y 6.4.2; TIBCO JasperReports Server Community Edition: versiones hasta e incluyendo la 6.4.2; TIBCO JasperReports Server for ActiveMatrix BPM: versiones hasta e incluyendo la 6.4.2; TIBCO Jaspersoft for AWS with Multi-Tenancy: versiones hasta e incluyendo la 6.4.2; TIBCO Jaspersoft Reporting and Analytics for AWS: versiones hasta e incluyendo la 6.4.2, de TIBCO Software Inc.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-12 CVE Reserved
- 2018-04-17 CVE Published
- 2023-07-08 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | <= 6.2.4 Search vendor "Tibco" for product "Jasperreports Server" and version " <= 6.2.4" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | <= 6.4.2 Search vendor "Tibco" for product "Jasperreports Server" and version " <= 6.4.2" | activematrix_bpm |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | <= 6.4.2 Search vendor "Tibco" for product "Jasperreports Server" and version " <= 6.4.2" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | 6.3.0 Search vendor "Tibco" for product "Jasperreports Server" and version "6.3.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | 6.3.2 Search vendor "Tibco" for product "Jasperreports Server" and version "6.3.2" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | 6.3.3 Search vendor "Tibco" for product "Jasperreports Server" and version "6.3.3" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | 6.4.0 Search vendor "Tibco" for product "Jasperreports Server" and version "6.4.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jasperreports Server Search vendor "Tibco" for product "Jasperreports Server" | 6.4.2 Search vendor "Tibco" for product "Jasperreports Server" and version "6.4.2" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jaspersoft Search vendor "Tibco" for product "Jaspersoft" | <= 6.4.2 Search vendor "Tibco" for product "Jaspersoft" and version " <= 6.4.2" | aws_with_multi-tenancy |
Affected
| ||||||
Tibco Search vendor "Tibco" | Jaspersoft Reporting And Analytics Search vendor "Tibco" for product "Jaspersoft Reporting And Analytics" | <= 6.4.2 Search vendor "Tibco" for product "Jaspersoft Reporting And Analytics" and version " <= 6.4.2" | aws |
Affected
|