CVE-2019-8986: TIBCO JasperReports Server XML Entity Expansion Vulnerability
The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-8986?
CVE-2019-8986 is the vulnerability that affects TIBCO Software Inc.'s TIBCO JasperReports Server and TIBCO JasperReports Server for ActiveMatrix BPM.
What is the severity of CVE-2019-8986?
The severity of CVE-2019-8986 is high, with a CVSS score of 7.7.
How does CVE-2019-8986 affect TIBCO JasperReports Server?
CVE-2019-8986 allows a malicious authenticated user to copy text files from the host operating system in TIBCO JasperReports Server.
Which versions of TIBCO JasperReports Server are affected by CVE-2019-8986?
TIBCO JasperReports Server versions up to and including 6.3.4 and versions up to and including 6.4.3 are affected by CVE-2019-8986.
How can I fix the vulnerability CVE-2019-8986?
To fix CVE-2019-8986, update TIBCO JasperReports Server to a version beyond 6.4.3.