CVE-2017-5528
Summary
| CVE | CVE-2017-5528 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-29 14:29:00 UTC |
| Updated | 2021-09-09 12:41:00 UTC |
| Description | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.2.0 and below). |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Jasperreports Server | 6.2.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.2.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.2.1 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.2.1 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.3.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.3.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.2.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.2.1 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.3.0 | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jasperreports Server Community Edition | All | All | All | All |
| Application | Tibco | Jasperreports Server For Activematrix Bpm | All | All | All | All |
| Application | Tibco | Jaspersoft | All | All | All | All |
| Application | Tibco | Jaspersoft For Aws With Multitenancy | All | All | All | All |
| Application | Tibco | Jaspersoft Reporting And Analytics | All | All | All | All |
| Application | Tibco | Jaspersoft Reporting And Analytics For Aws | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIBCO Security Advisory: June 28, 2017 - TIBCO JasperReports Server - 2017-5528 | TIBCO Software | CONFIRM | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.