CVE-2022-22773Cross-site Scripting in Jasperreports Server

Severity
5.4MEDIUMNVD
CNA7.7
EPSS
0.6%
top 31.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 18

Description

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affecte

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-mf8h-5f5r-mpg8: The REST API component of TIBCO Software Inc2022-05-18
CVEList
TIBCO JasperReports Server Reflected Cross Site Scripting (XSS) vulnerability2022-05-17
CVE-2022-22773 — Cross-site Scripting | cvebase