← Back to CVE List
Vulnerability Intelligence Report
TIBCO JasperReports Server Fails To Enforce Access Restrictions

CVE-2020-9409

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:3.38%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
TIBCO Software Inc. TIBCO JasperReports Server unspecified <= 7.1.1 (affected)
TIBCO Software Inc. TIBCO JasperReports Server for AWS Marketplace unspecified <= 7.1.1 (affected)
TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM unspecified <= 7.1.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.375%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTIBCO Software Inc. · Vendor · USA
Reserved2020-02-26T00:00:00
Published2020-05-20T12:25:13
Patch Date2020-05-19
Last Updated2024-09-17T01:16:13

LINK COPIED TO CLIPBOARD