← Back

CVE-2018-5431

nvd nist
Published: Apr 17, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3; 6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

Affected (10)

3 products
Jasperreports Server
Jaspersoft
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Tibco
Up to 6.2.4
Up to 6.4.2
Up to 6.4.2
Version 6.3.0
Version 6.3.2
Version 6.3.3
Version 6.4.0
Version 6.4.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.4.2
Up to 6.4.2

Timeline

No history available yet.