TIBCO JasperReports Server cross-site vulnerabilities
Summary
| CVE | CVE-2017-5528 |
|---|---|
| State | PUBLISHED |
| Assigner | tibco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-29 14:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.2.0 and below). |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-352 | Cross site scripting
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.0 | [email protected] | Secondary | 5.7 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
| 3.0 | CNA | DECLARED | 5.7 | MEDIUM | CVSS:3.0/A:N/AC:L/AV:N/C:H/I:N/PR:L/S:U/UI:R |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Jasperreports Server | 6.2.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.2.1 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.3.0 | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jaspersoft | All | All | All | All |
| Application | Tibco | Jaspersoft Reporting And Analytics | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TIBCO Software Inc. | TIBCO JasperReports Server | affected unspecified 6.1.1 custom | Not specified |
| CNA | TIBCO Software Inc. | TIBCO JasperReports Server | affected 6.2.0 | Not specified |
| CNA | TIBCO Software Inc. | TIBCO JasperReports Server | affected 6.2.1 | Not specified |
| CNA | TIBCO Software Inc. | TIBCO JasperReports Server | affected 6.3.0 | Not specified |
| CNA | TIBCO Software Inc. | TIBCO JasperReports Server Community Edition | affected unspecified 6.3.0 custom | Not specified |
| CNA | TIBCO Software Inc. | TIBCO JasperReports Server For ActiveMatrix BPM | affected unspecified 6.2.0 custom | Not specified |
| CNA | TIBCO Software Inc. | TIBCO Jaspersoft For AWS With Multi-Tenancy | affected unspecified 6.3.0 custom | Not specified |
| CNA | TIBCO Software Inc. | TIBCO Jaspersoft Reporting And Analytics For AWS | affected unspecified 6.3.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIBCO Security Advisory: June 28, 2017 - TIBCO JasperReports Server - 2017-5528 | TIBCO Software | af854a3a-2127-422b-91ae-364da2661108 | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.