CVE-2018-5431: TIBCO JasperReports Server Cross Site Scripting Vulnerability
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TIBCO JasperReports Serverto a version that resolves this vulnerability.Fixed in 6.2.5 - Upgrade
Upgrade
TIBCO JasperReports Serverto a version that resolves this vulnerability.Fixed in 6.3.4 - Upgrade
Upgrade
TIBCO JasperReports Serverto a version that resolves this vulnerability.Fixed in 6.4.3 - Upgrade
Upgrade
TIBCO JasperReports Server Community Editionto a version that resolves this vulnerability.Fixed in 6.4.3 - Upgrade
Upgrade
TIBCO JasperReports Server for ActiveMatrix BPMto a version that resolves this vulnerability.Fixed in 6.4.3 - Upgrade
Upgrade
TIBCO Jaspersoft for AWS with Multi-Tenancyto a version that resolves this vulnerability.Fixed in 6.4.3 - Upgrade
Upgrade
TIBCO Jaspersoft Reporting and Analytics for AWSto a version that resolves this vulnerability.Fixed in 6.4.3
Event History
Frequently Asked Questions
What is CVE-2018-5431?
CVE-2018-5431 is a vulnerability in the domain designer component of TIBCO JasperReports Server that allows remote attackers to execute arbitrary code or cause a denial of service.
What software is affected by CVE-2018-5431?
CVE-2018-5431 affects TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS.
What is the severity of CVE-2018-5431?
The severity of CVE-2018-5431 is medium, with a CVSS score of 5.4.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers to execute arbitrary code or cause a denial of service.
How can I mitigate CVE-2018-5431?
To mitigate CVE-2018-5431, update your TIBCO JasperReports Server to version 6.2.4 or higher.