CVE-2022-41561: TIBCO JasperReports Server RCE Vulnerability
The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows a privileged/administrative attacker with network access to execute Remote Code Execution to obtain a reverse shell on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 8.0.2 and below, TIBCO JasperReports Server: version 8.1.0, TIBCO JasperReports Server - Community Edition: versions 8.1.0 and below, TIBCO JasperReports Server - Developer Edition: versions 8.1.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 8.0.2 and below, TIBCO JasperReports Server for AWS Marketplace: version 8.1.0, TIBCO JasperReports Server for Microsoft Azure: versions 8.0.2 and below, and TIBCO JasperReports Server for Microsoft Azure: version 8.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-41561?
CVE-2022-41561 is a vulnerability in the JNDI Data Sources component of TIBCO JasperReports Server.
What is the severity of CVE-2022-41561?
CVE-2022-41561 has a severity rating of 7.2 (Critical).
Which versions of TIBCO JasperReports Server are affected by CVE-2022-41561?
CVE-2022-41561 affects TIBCO JasperReports Server versions 8.0.2 and 8.1.0.
How can I fix CVE-2022-41561?
To fix CVE-2022-41561, it is recommended to apply the patches provided by TIBCO Software Inc.
Where can I find more information about CVE-2022-41561?
More information about CVE-2022-41561 can be found on the TIBCO Software Inc. support advisories page.