CVE-2021-35494Race Condition in Software INC Tibco Jasperreports Server

CWE-362Race Condition3 documents3 sources
Severity
5.3MEDIUMNVD
CNA5.7
EPSS
0.2%
top 63.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 24

Description

The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contain a race condition that allows a low privileged authenticated attacker via the REST API to

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-95fh-3xq2-rfcx: The Rest API component of TIBCO Software Inc2022-05-24
CVEList
TIBCO JasperReports unauthorized access to temporary object2021-10-12
CVE-2021-35494 — Race Condition | cvebase