← Back to CVE List
Vulnerability Intelligence Report
TIBCO JasperReports Library Directory Traversal Vulnerability

CVE-2018-18809

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:79.84%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
TIBCO Software Inc. TIBCO JasperReports Library unspecified <= 6.3.4 (affected), 6.4.1 (affected), 6.4.2 (affected), 6.4.21 (affected), 7.1.0 (affected), 7.2.0 (affected)
TIBCO Software Inc. TIBCO JasperReports Library Community Edition unspecified <= 6.7.0 (affected)
TIBCO Software Inc. TIBCO JasperReports Library for ActiveMatrix BPM unspecified <= 6.4.21 (affected)
TIBCO Software Inc. TIBCO JasperReports Server unspecified <= 6.3.4 (affected), 6.4.0 (affected), 6.4.1 (affected), 6.4.2 (affected), 6.4.3 (affected), 7.1.0 (affected)
TIBCO Software Inc. TIBCO JasperReports Server Community Edition unspecified <= 6.4.3 (affected), 7.1.0 (affected)
TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM unspecified <= 6.4.3 (affected)
TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy unspecified <= 7.1.0 (affected)
TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS unspecified <= 7.1.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
79.836%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTIBCO Software Inc. · Vendor · USA
Reserved2018-10-29T00:00:00
Published2019-03-07T22:00:00
Patch Date2019-03-06
Last Updated2025-10-21T23:45:42

LINK COPIED TO CLIPBOARD