CVE-2022-22771: TIBCO JasperReports Library Directory Traversal Vulnerability
The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: version 7.9.0, TIBCO JasperReports Library for ActiveMatrix BPM: version 7.9.0, TIBCO JasperReports Server: versions 7.9.0 and 7.9.1, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and 7.9.1, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and 7.9.1, and TIBCO JasperReports Server for Microsoft Azure: version 7.9.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22771?
CVE-2022-22771 is a vulnerability in the Server component of TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure.
How severe is CVE-2022-22771?
CVE-2022-22771 has a severity rating of 8.8 (critical).
What software is affected by CVE-2022-22771?
CVE-2022-22771 affects TIBCO JasperReports Library 7.9.0, TIBCO JasperReports Library for ActiveMatrix BPM 7.9.0, TIBCO JasperReports Server 7.9.0, TIBCO JasperReports Server for AWS Marketplace 7.9.0, TIBCO JasperReports Server for ActiveMatrix BPM 7.9.0, and TIBCO JasperReports Server for Microsoft Azure 7.9.0.
How do I fix CVE-2022-22771?
To fix CVE-2022-22771, it is recommended to upgrade to a patched version of the affected software when it becomes available. Please refer to the TIBCO security advisories for more information.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-22771?
The Common Weakness Enumeration (CWE) ID for CVE-2022-22771 is 22.