VDB
BDU%3A2023-00914
BDU%3A2023-00914
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость серверной библиотеки приложений для создания отчетов TIBCO JasperReports Library, JasperReports Library for ActiveMatrix BPM, JasperReports Server, JasperReports Server for AWS Marketplace, JasperReports Server for ActiveMatrix BPM, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| TIBCO Software Inc. | JasperReports Library, JasperReports Library for ActiveMatrix BPM, JasperReports Server Community Edition, JasperReports Server for ActiveMatrix BPM, Jaspersoft Reporting and Analytics for AWS, Jaspersoft for AWS with Multi-Tenancy |
Timeline
- Mar 1, 2023 CVE Published
- Feb 6, 2025 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-18809 url
- http://packetstormsecurity.com/files/154406/Tibco-JasperSoft-Path-Traversal.html url
- http://seclists.org/fulldisclosure/2019/Sep/17 url
- http://www.securityfocus.com/bid/107351 url
- http://www.tibco.com/services/support/advisories url
- https://cybersecurityworks.com/zerodays/cve-2018-18809-tibco.html url
- https://security.elarlang.eu/cve-2018-18809-path-traversal-in-tibco-jaspersoft.html url
- https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809 url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url