⚠ Actively exploited
Added to CISA KEV on 2022-12-29. Federal agencies required to patch by 2023-01-19. Required action: Apply updates per vendor instructions..
CVE-2018-5430 — Path Traversal in Software INC Tibco Jasperreports Server
Severity
8.8HIGHNVD
EPSS
41.4%
top 2.59%
CISA KEV
KEV
Added 2022-12-29
Due 2023-01-19
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedApr 17
KEV addedDec 29
Latest updateJan 5
KEV dueJan 19
CISA Required Action: Apply updates per vendor instructions.
Description
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: ve…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages8 packages
🔴Vulnerability Details
4💥Exploits & PoCs
1🔍Detection Rules
1Suricata
▶