CVE-2018-18808: TIBCO JasperReports Server Privilege Escalation Via Race Condition
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability that may allow any users with domain save privileges to gain superuser privileges. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2018-18808?
CVE-2018-18808 is a vulnerability in TIBCO JasperReports Server that allows a race condition and can result in unauthorized access to certain functionality.
How does CVE-2018-18808 affect TIBCO JasperReports Server?
CVE-2018-18808 affects TIBCO JasperReports Server versions up to 6.3.4, 6.4.3, and 7.1.0 and allows unauthorized access to certain functionality.
What is the severity of CVE-2018-18808?
The severity of CVE-2018-18808 is high with a CVSS score of 7.5.
How can I fix CVE-2018-18808?
To fix CVE-2018-18808, upgrade to a patched version of TIBCO JasperReports Server.
Where can I find more information about CVE-2018-18808?
You can find more information about CVE-2018-18808 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/107350), [TIBCO Security Advisories](https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-server-2018-18808).