The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3.
2019-03-07T22:29:00.540
2024-11-21T04:50:45.770
Modified
CVSSv3.1: 7.7 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tibco | jasperreports_server | ≤ 6.3.4 | Yes |
Application | tibco | jasperreports_server | ≤ 6.4.3 | Yes |
Application | tibco | jasperreports_server | 6.4.0 | Yes |
Application | tibco | jasperreports_server | 6.4.1 | Yes |
Application | tibco | jasperreports_server | 6.4.2 | Yes |
Application | tibco | jasperreports_server | 6.4.3 | Yes |