← Back to CVE List
Vulnerability Intelligence Report
TIBCO JasperReports Server Information Disclosure Vulnerability

CVE-2018-5430

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.7
HIGH
Exploitability:3.2
Impact Score:4.0
EPSS Probability:48.75%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected Products & Versions

Vendor Product Affected Versions
TIBCO Software Inc. TIBCO JasperReports Server unspecified <= 6.2.4 (affected), 6.3.0 (affected), 6.3.2 (affected), 6.3.3 (affected), 6.4.0 (affected), 6.4.2 (affected)
TIBCO Software Inc. TIBCO JasperReports Server Community Edition unspecified <= 6.4.2 (affected)
TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM unspecified <= 6.4.2 (affected)
TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy unspecified <= 6.4.2 (affected)
TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS unspecified <= 6.4.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
48.753%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTIBCO Software Inc. · Vendor · USA
Reserved2018-01-12T00:00:00
Published2018-04-17T18:00:00
Patch Date2018-04-17
Last Updated2025-10-21T23:45:52

LINK COPIED TO CLIPBOARD