CVE-2018-5430
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
Weaknesses (CWE)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| TIBCO Software Inc. | TIBCO JasperReports Server | unspecified <= 6.2.4 (affected), 6.3.0 (affected), 6.3.2 (affected), 6.3.3 (affected), 6.4.0 (affected), 6.4.2 (affected) |
| TIBCO Software Inc. | TIBCO JasperReports Server Community Edition | unspecified <= 6.4.2 (affected) |
| TIBCO Software Inc. | TIBCO JasperReports Server for ActiveMatrix BPM | unspecified <= 6.4.2 (affected) |
| TIBCO Software Inc. | TIBCO Jaspersoft for AWS with Multi-Tenancy | unspecified <= 6.4.2 (affected) |
| TIBCO Software Inc. | TIBCO Jaspersoft Reporting and Analytics for AWS | unspecified <= 6.4.2 (affected) |
References & Technical Advisories
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | TIBCO Software Inc. · Vendor · USA |
| Reserved | 2018-01-12T00:00:00 |
| Published | 2018-04-17T18:00:00 |
| Patch Date | 2018-04-17 |
| Last Updated | 2025-10-21T23:45:52 |
Community Chatter & Buzz