8.8
CVE-2022-22771
- EPSS 2.45%
- Veröffentlicht 15.03.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:24
- Erkennungen
TIBCO JasperReports Library Directory Traversal Vulnerability
The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: version 7.9.0, TIBCO JasperReports Library for ActiveMatrix BPM: version 7.9.0, TIBCO JasperReports Server: versions 7.9.0 and 7.9.1, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and 7.9.1, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and 7.9.1, and TIBCO JasperReports Server for Microsoft Azure: version 7.9.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tibco ≫ Jasperreports Library Version 7.9.0 SwPlatform -
Tibco ≫ Jasperreports Library Version 7.9.0 SwPlatform activematrix_bpm
Tibco ≫ Jasperreports Server Version 7.9.0 SwPlatform -
Tibco ≫ Jasperreports Server Version 7.9.0 SwPlatform activematrix_bpm
Tibco ≫ Jasperreports Server Version 7.9.0 SwPlatform aws_marketplace
Tibco ≫ Jasperreports Server Version 7.9.0 SwPlatform azure
Tibco ≫ Jasperreports Server Version 7.9.1 SwPlatform -
Tibco ≫ Jasperreports Server Version 7.9.1 SwPlatform activematrix_bpm
Tibco ≫ Jasperreports Server Version 7.9.1 SwPlatform aws_marketplace
Tibco ≫ Jasperreports Server Version 7.9.1 SwPlatform azure
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.45% | 0.83 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| Tibco | 9.9 | 3.1 | 6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://www.tibco.com/services/support/advisories
https://www.tibco.com/support/advisories/2022/03/tibco-security-advisory-march-15-2022-tibco-jasperreports-library-2022-22771