CVE-2018-5431

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/04/2018
Last modified:
09/10/2019

Description

The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:* 6.2.4 (including)
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:* 6.4.2 (including)
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:community:*:*:* 6.4.2 (including)
cpe:2.3:a:tibco:jasperreports_server:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.3.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.3.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jaspersoft:*:*:*:*:*:aws_with_multi-tenancy:*:* 6.4.2 (including)
cpe:2.3:a:tibco:jaspersoft_reporting_and_analytics:*:*:*:*:*:aws:*:* 6.4.2 (including)