⚠ Actively exploited
Added to CISA KEV on 2022-12-29. Federal agencies required to patch by 2023-01-19. Required action: Apply updates per vendor instructions..

CVE-2018-5430Path Traversal in Software INC Tibco Jasperreports Server

Severity
8.8HIGHNVD
EPSS
41.4%
top 2.59%
CISA KEV
KEV
Added 2022-12-29
Due 2023-01-19
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 17
KEV addedDec 29
Latest updateJan 5
KEV dueJan 19
CISA Required Action: Apply updates per vendor instructions.

Description

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: ve

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

🔴Vulnerability Details

4
GHSA
GHSA-782f-h7v4-m7wc: The Spring web flows of TIBCO Software Inc2022-05-13
OSV
CVE-2018-5430: The Spring web flows of TIBCO Software Inc2018-04-17
CVEList
TIBCO JasperReports Server Information Disclosure Vulnerability2018-04-17
VulnCheck
TIBCO JasperReports Server Information Disclosure Vulnerability2018

💥Exploits & PoCs

1
Exploit-DB
JasperReports - (Authenticated) File Read2018-05-03

🔍Detection Rules

1
Suricata
ET EXPLOIT TIBCO JasperReports Authenticated Arbitrary File Read Attempt (CVE-2018-5430)2023-01-05

📋Vendor Advisories

1
CISA
TIBCO JasperReports Server Information Disclosure Vulnerability2022-12-29

💬Community

2
Bugzilla
CVE-2018-5430 jasperreports: read-only access to the contents of the web application for authenticated user2018-04-23
Bugzilla
CVE-2018-5429 CVE-2018-5430 CVE-2018-5431 jasperreports: various flaws [fedora-all]2018-04-23
CVE-2018-5430 — Path Traversal | cvebase