CVE-2020-9409Incorrect Default Permissions in Software INC Tibco Jasperreports Server

Severity
9.8CRITICALNVD
EPSS
3.1%
top 13.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 24

Description

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j2v4-xwh5-47fc: The administrative UI component of TIBCO Software Inc2022-05-24
CVEList
TIBCO JasperReports Server Fails To Enforce Access Restrictions2020-05-20
CVE-2020-9409 — Incorrect Default Permissions | cvebase