First published: Thu Mar 07 2019(Updated: )
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
Credit: security@tibco.com security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tibco Jasperreports Library | <=6.4.21 | |
Tibco Jasperreports Library | <=6.7.0 | |
Tibco Jasperreports Library | =6.3.4 | |
Tibco Jasperreports Library | =6.4.1 | |
Tibco Jasperreports Library | =6.4.2 | |
Tibco Jasperreports Library | =6.4.21 | |
Tibco Jasperreports Library | =7.1.0 | |
Tibco Jasperreports Library | =7.2.0 | |
Tibco Jasperreports Server | <=6.4.3 | |
Tibco Jasperreports Server | <=6.4.3 | |
Tibco Jasperreports Server | =6.3.4 | |
Tibco Jasperreports Server | =6.4.0 | |
Tibco Jasperreports Server | =6.4.1 | |
Tibco Jasperreports Server | =6.4.2 | |
Tibco Jasperreports Server | =6.4.3 | |
Tibco Jasperreports Server | =7.1.0 | |
Tibco Jasperreports Server | =7.1.0 | |
Tibco Jaspersoft | <=7.1.0 | |
Tibco Jaspersoft Reporting And Analytics | <=7.1.0 | |
TIBCO JasperReports | ||
<=6.4.21 | ||
<=6.7.0 | ||
=6.3.4 | ||
=6.4.1 | ||
=6.4.2 | ||
=6.4.21 | ||
=7.1.0 | ||
=7.2.0 | ||
<=6.4.3 | ||
<=6.4.3 | ||
=6.3.4 | ||
=6.4.0 | ||
=6.4.1 | ||
=6.4.2 | ||
=6.4.3 | ||
=7.1.0 | ||
=7.1.0 | ||
<=7.1.0 | ||
<=7.1.0 |
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO JasperReports Library versions 6.3.4 and below update to version 6.3.5 or higher TIBCO JasperReports Library versions 6.4.1, 6.4.2, and 6.4.21 update to version 6.4.22 or higher TIBCO JasperReports Library version 7.1.0 update to version 7.1.1 or higher TIBCO JasperReports Library version 7.2.0 update to version 7.2.1 or higher TIBCO JasperReports Library Community Edition versions 6.7.0 and below update to version 6.7.1 or higher TIBCO JasperReports Library for ActiveMatrix BPM versions 6.4.21 and below update to version 6.4.22 or higher TIBCO JasperReports Server versions 6.3.4 and below update to version 6.3.5 or higher TIBCO JasperReports Server versions 6.4.0, 6.4.1, 6.4.2, and 6.4.3 update to version 6.4.4 or higher TIBCO JasperReports Server version 7.1.0 update to version 7.1.1 or higher TIBCO JasperReports Server Community Edition versions 7.1.0 and below update to version 7.1.1 or higher TIBCO JasperReports Server for ActiveMatrix BPM versions 6.4.3 and below update to version 6.4.4 or higher TIBCO Jaspersoft for AWS with Multi-Tenancy versions 7.1.0 and below update to version 7.1.1 or higher TIBCO Jaspersoft Reporting and Analytics for AWS versions 7.1.0 and below update to version 7.1.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18809 is a directory traversal vulnerability in the TIBCO JasperReports Library.
CVE-2018-18809 allows web server users to access contents of the host system.
The TIBCO JasperReports Library is affected by CVE-2018-18809.
To fix CVE-2018-18809, update to the latest version of the TIBCO JasperReports Library.
You can find more information about CVE-2018-18809 in TIBCO's security advisory: <a href="https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809">TIBCO Security Advisory</a>.