CVE-2017-5529 Information

Description

JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below) TIBCO JasperReports Library for ActiveMatrix BPM (versions 6.2.0 and below) TIBCO JasperReports Professional (versions 6.2.1 and below and 6.3.0) TIBCO JasperReports Server (versions 6.1.1 and below 6.2.0 6.2.1 6.3.0) TIBCO JasperReports Server Community Edition (versions 6.3.0 and below) TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below) TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.3.0 and below) TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.3.0 and below) and TIBCO Jaspersoft Studio for ActiveMatrix BPM (versions 6.2.0 and below).

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Reference

http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html https://www.oracle.com/security-alerts/cpuapr2020.html https://www.tibco.com/support/advisories/2017/06/tibco-security-advisory-june-28-2017-tibco-jasperreports-server-2017-0

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: