CVE-2017-5533
Summary
| CVE | CVE-2017-5533 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-15 21:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent remote access to all the contents of the web application, including key configuration files. Affected releases are TIBCO JasperReports Server 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jaspersoft | 6.4.0 | All | All | All |
| Application | Tibco | Jaspersoft | 6.4.0 | All | All | All |
| Application | Tibco | Jaspersoft Reporting And Analytics | 6.4.0 | All | All | All |
| Application | Tibco | Jaspersoft Reporting And Analytics | 6.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CPU July 2018 | CONFIRM | www.oracle.com | |
| Multiple TIBCO Products CVE-2017-5533 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| TIBCO Security Advisory: November 15, 2017 - TIBCO JasperReports Server - 2017-5533 | TIBCO Software | CONFIRM | www.tibco.com | Issue Tracking, Vendor Advisory |
| CPU Oct 2018 | CONFIRM | www.oracle.com | |
| Oracle Critical Patch Update Advisory - April 2020 | N/A | www.oracle.com | |
| Oracle Critical Patch Update Advisory - April 2019 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.