← All CVEs

CVE-2018-5430

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-12-29Remediation due 2023-01-19

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

8.8
CVSS
49.6%
EPSS (exploit prob.)
99th
EPSS percentile
2018-04-17
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22CWE-200

Affected products

VendorProductAffected versions
tibcojasperreports_server<= 6.2.4
tibcojasperreports_server<= 6.4.2
tibcojasperreports_server<= 6.4.2
tibcojasperreports_server6.3.0
tibcojasperreports_server6.3.2
tibcojasperreports_server6.3.3
tibcojasperreports_server6.4.0
tibcojasperreports_server6.4.2
tibcojaspersoft<= 6.4.2
tibcojaspersoft_reporting_and_analytics<= 6.4.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-5430