BIT-jasperreports-2020-9409

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jasperreports/BIT-jasperreports-2020-9409.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-jasperreports-2020-9409
Aliases
  • CVE-2020-9409
Published
2024-03-06T11:00:35.562Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.

Database specific
{
    "cpes": [
        "cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:-:*:*",
        "cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:*",
        "cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:aws_marketplace:*:*"
    ],
    "severity": "Critical"
}
References

Affected packages

Bitnami / jasperreports

Package

Name
jasperreports
Purl
pkg:bitnami/jasperreports

Severity

  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jasperreports/BIT-jasperreports-2020-9409.json"