CVE-2019-8986
Summary
| CVE | CVE-2019-8986 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-07 22:29:00 UTC |
| Updated | 2022-01-01 20:15:00 UTC |
| Description | The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.1 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.2 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.3 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.0 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.1 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.2 | All | All | All |
| Application | Tibco | Jasperreports Server | 6.4.3 | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
| Application | Tibco | Jasperreports Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| TIBCO Security Advisory: March 6, 2019 - TIBCO JasperReports Server - 2019-8986 | TIBCO Software | CONFIRM | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: TIBCO would like to extend its appreciation to Julien Szlamowicz and Sebastien Dudek of Synacktiv for discovery of this vulnerability.
There are currently no legacy QID mappings associated with this CVE.