CVE-2021-35496XML External Entity (XXE) Injection in Software INC Tibco Jasperreports Server

Severity
7.5HIGHNVD
EPSS
0.3%
top 42.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 24

Description

The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a difficult to exploit vulnerability that allows a low privileged attacker with

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-7qj3-x497-55f5: The XMLA Connections component of TIBCO Software Inc2022-05-24
CVEList
TIBCO JasperReports XML Eternal Entity (XXE) vulnerability2021-10-12
CVE-2021-35496 — XML External Entity (XXE) Injection | cvebase