CVE-2017-5532
Last modified
CVE-2017-5532 is a vulnerability of currently unknown severity. A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS, TIBCO Jaspersoft Studio, and TIBCO Jaspersoft Studio for ActiveMatrix BPM may allow a subset of authorized users to perform persistent cross-site scripting (XSS) attacks. Affected releases are TIBCO JasperReports Server 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2; 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0 and below, TIBCO JasperReports Library 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2; 6.4.0; 6.4.1, TIBCO JasperReports Library for ActiveMatrix BPM 6.4.1 and below, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0 and below, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0 and below, TIBCO Jaspersoft Studio 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2; 6.4.0, and TIBCO Jaspersoft Studio for ActiveMatrix BPM 6.4.0 and below.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS, TIBCO Jaspersoft Studio, and TIBCO Jaspersoft Studio for ActiveMatrix BPM may allow a subset of authorized users to perform persistent cross-site scripting (XSS) attacks. Affected releases are TIBCO JasperReports Server 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2; 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0 and below, TIBCO JasperReports Library 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2; 6.4.0; 6.4.1, TIBCO JasperReports Library for ActiveMatrix BPM 6.4.1 and below, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0 and below, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0 and below, TIBCO Jaspersoft Studio 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2; 6.4.0, and TIBCO Jaspersoft Studio for ActiveMatrix BPM 6.4.0 and below.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tibco | Jasperreports Server | <= 6.2.3 |
| Tibco | Jasperreports Server | 6.3.0 |
| Tibco | Jasperreports Server | 6.3.1 |
| Tibco | Jasperreports Server | 6.3.2 |
| Tibco | Jasperreports Server | 6.4.0 |
| Tibco | Jasperreports Server | <= 6.4.0 |
| Tibco | Jasperreports Library | <= 6.2.3 |
| Tibco | Jasperreports Library | 6.3.0 |
| Tibco | Jasperreports Library | 6.3.1 |
| Tibco | Jasperreports Library | 6.3.2 |
| Tibco | Jasperreports Library | 6.4.0 |
| Tibco | Jasperreports Library | 6.4.1 |
| Tibco | Jasperreports Library | <= 6.4.1 |
| Tibco | Jaspersoft | <= 6.4.0 |
| Tibco | Jaspersoft Reporting And Analytics | <= 6.4.0 |
| Tibco | Jaspersoft Studio | <= 6.2.3 |
| Tibco | Jaspersoft Studio | 6.3.0 |
| Tibco | Jaspersoft Studio | 6.3.1 |
| Tibco | Jaspersoft Studio | 6.3.2 |
| Tibco | Jaspersoft Studio | 6.4.0 |
| Tibco | Jaspersoft Studio | <= 6.4.0 |
References
- http://www.securityfocus.com/bid/101873Issue Tracking, Third Party Advisory, VDB Entry
- https://www.tibco.com/support/advisories/2017/11/tibco-security-advisory-november-15-2017-tibco-jasperreports-2017-5532Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/101873Issue Tracking, Third Party Advisory, VDB Entry
- https://www.tibco.com/support/advisories/2017/11/tibco-security-advisory-november-15-2017-tibco-jasperreports-2017-5532Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5532?
How severe is CVE-2017-5532?
How do I fix CVE-2017-5532?
Are you affected by CVE-2017-5532?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
