Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-35496


The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to interfere with XML processing in the affected component. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.2.1 and below, TIBCO JasperReports Server: versions 7.5.0 and 7.5.1, TIBCO JasperReports Server: version 7.8.0, TIBCO JasperReports Server: version 7.9.0, TIBCO JasperReports Server - Community Edition: versions 7.8.0 and below, TIBCO JasperReports Server - Developer Edition: versions 7.9.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and below, and TIBCO JasperReports Server for Microsoft Azure: version 7.8.0.


Published

2021-10-12T18:15:08.310

Last Modified

2024-11-21T06:12:22.980

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tibco jasperreports_server ≤ 7.2.1 Yes
Application tibco jasperreports_server ≤ 7.8.0 Yes
Application tibco jasperreports_server ≤ 7.8.0 Yes
Application tibco jasperreports_server ≤ 7.9.0 Yes
Application tibco jasperreports_server ≤ 7.9.0 Yes
Application tibco jasperreports_server ≤ 7.9.0 Yes
Application tibco jasperreports_server 7.5.0 Yes
Application tibco jasperreports_server 7.5.1 Yes
Application tibco jasperreports_server 7.8.0 Yes
Application tibco jasperreports_server 7.9.0 Yes

References