⚠ Actively exploited
Added to CISA KEV on 2022-12-29. Federal agencies required to patch by 2023-01-19. Required action: Apply updates per vendor instructions..

CVE-2018-18809Path Traversal in Software INC Tibco Jasperreports Library

CWE-22Path Traversal7 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
93.9%
top 0.12%
CISA KEV
KEV
Added 2022-12-29
Due 2023-01-19
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMar 7
KEV addedDec 29
Latest updateJan 5
KEV dueJan 19
CISA Required Action: Apply updates per vendor instructions.

Description

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages12 packages

🔴Vulnerability Details

3
GHSA
GHSA-2qh3-cx4w-cf3x: The default server implementation of TIBCO Software Inc2022-05-13
CVEList
TIBCO JasperReports Library Directory Traversal Vulnerability2019-03-07
VulnCheck
TIBCO JasperReports Library Directory Traversal Vulnerability2018

💥Exploits & PoCs

1
Nuclei
TIBCO JasperReports Library - Directory Traversal

🔍Detection Rules

1
Suricata
ET EXPLOIT TIBCO JasperReports Directory Traversal Attempt (CVE-2018-18809)2023-01-05

📋Vendor Advisories

1
CISA
TIBCO JasperReports Library Directory Traversal Vulnerability2022-12-29
CVE-2018-18809 — Path Traversal | cvebase