First published: Wed Apr 17 2024(Updated: )
Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO JasperReports | >=8.0.4<=8.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3323 is a critical vulnerability due to the potential for Cross Site Scripting attacks that can compromise user session security.
To fix CVE-2024-3323, upgrade TIBCO JasperReports Server to version 8.2.1 or later, which includes security patches.
CVE-2024-3323 affects TIBCO JasperReports Server versions 8.0.4 and 8.2.0.
The risks associated with CVE-2024-3323 include unauthorized access to user data and potential session hijacking through malicious script injection.
You can identify if your system is vulnerable to CVE-2024-3323 by checking if you are using TIBCO JasperReports Server version 8.0.4 or 8.2.0.