CVE-2018-5431
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
17/04/2018
Last modified:
09/10/2019
Description
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:* | 6.2.4 (including) | |
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:* | 6.4.2 (including) | |
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:community:*:*:* | 6.4.2 (including) | |
cpe:2.3:a:tibco:jasperreports_server:6.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:tibco:jasperreports_server:6.3.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:tibco:jasperreports_server:6.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:tibco:jasperreports_server:6.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:tibco:jasperreports_server:6.4.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:tibco:jaspersoft:*:*:*:*:*:aws_with_multi-tenancy:*:* | 6.4.2 (including) | |
cpe:2.3:a:tibco:jaspersoft_reporting_and_analytics:*:*:*:*:*:aws:*:* | 6.4.2 (including) |
To consult the complete list of CPE names with products and versions, see this page