Security Advsiory regarding TIBCO JasperReports Server

Security Advsiory regarding TIBCO JasperReports Server

book

Article ID: KB0108081

calendar_today

Updated On:

Products Versions
TIBCO JasperReports Server 6.3.4 and below, 6.4.0, 6.4.1, 6.4.2, and 6.4.3

Description

TIBCO JasperReports Server XML Entity Expansion Vulnerability

  Original release date: March 6, 2019
  Last revised: --
  Source: TIBCO Software Inc.

Description

  The component listed above contains a vulnerability that may allow a
  malicious authenticated user to copy text files from the host operating
  system.


Impact

  The impact of this vulnerability includes the theoretical possibility
  of accessing the contents of any text file on the file system that is
  accessible to the operating system account running the affected component.
  Depending on how affected system is deployed, credentials to access other
  systems might be revealed.

  CVSS v3 Base Score: 7.7 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
 

Issue/Introduction

Security Advsiory regarding TIBCO JasperReports Server

Environment

Systems Affected TIBCO JasperReports® Server versions 6.3.4 and below TIBCO JasperReports® Server versions 6.4.0, 6.4.1, 6.4.2, and 6.4.3 TIBCO JasperReports® Server for ActiveMatrix® BPM versions 6.4.3 and below The following components are affected: * SOAP API

Resolution

Solution

  TIBCO has released updated versions of the affected components which address
  these issues.

  For each affected system, update to the corresponding software versions:

  TIBCO JasperReports® Server versions 6.3.4 and below update to version 6.3.5
    or higher
  TIBCO JasperReports® Server versions 6.4.0, 6.4.1, 6.4.2, and 6.4.3 update to
    version 6.4.4 or higher

  TIBCO JasperReports® Server for ActiveMatrix® BPM versions 6.4.3 and below
    update to version 6.4.4 or higher

Additional Information

Acknowledgments

  TIBCO would like to extend its appreciation to Julien Szlamowicz and
  Sebastien Dudek of Synacktiv for discovery of this vulnerability.


References

  http://www.tibco.com/services/support/advisories
  CVE-2019-8986