CVE-2024-3323: Reflected Cross Site Scripting (XSS) vulnerability
Cross Site Scripting in
UI Request/Response Validation
in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3323?
CVE-2024-3323 is a critical vulnerability due to the potential for Cross Site Scripting attacks that can compromise user session security.
How do I fix CVE-2024-3323?
To fix CVE-2024-3323, upgrade TIBCO JasperReports Server to version 8.2.1 or later, which includes security patches.
What versions of TIBCO JasperReports Server are affected by CVE-2024-3323?
CVE-2024-3323 affects TIBCO JasperReports Server versions 8.0.4 and 8.2.0.
What are the risks associated with CVE-2024-3323?
The risks associated with CVE-2024-3323 include unauthorized access to user data and potential session hijacking through malicious script injection.
How can I identify if my system is vulnerable to CVE-2024-3323?
You can identify if your system is vulnerable to CVE-2024-3323 by checking if you are using TIBCO JasperReports Server version 8.0.4 or 8.2.0.