TIBCO takes its security responsibilities very seriously. This page provides information about TIBCO security and how customers or security researchers can contact TIBCO to report or ask about a security issue.
TIBCO Security Advisory: May 19, 2020 - TIBCO JasperReports Server
TIBCO JasperReports Server Fails To Enforce Access Restrictions
Original release date: May 19, 2020
Source: TIBCO Software Inc.
- TIBCO JasperReports Server versions 7.1.1 and below
- TIBCO JasperReports Server for AWS Marketplace versions 7.1.1 and below
- TIBCO JasperReports Server for ActiveMatrix BPM versions 7.1.1 and below
The following component is affected:
- administrative UI
The component listed above contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating.
The impact of this vulnerability includes the possibility that an unauthenticated user obtains JasperReports Server "superuser" permission, and further might be able to execute arbitrary code with the system account that started the affected component.
CVSS v3 Base Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
TIBCO has released updated versions of the affected systems which address this issue:
- TIBCO JasperReports Server versions 7.1.1 and below update to version 7.1.3 or higher
- TIBCO JasperReports Server for AWS Marketplace versions 7.1.1 and below update to version 7.2.0 or higher
- TIBCO JasperReports Server for ActiveMatrix BPM versions 7.1.1 and below update to version 7.1.3 or higher