CVE-2021-35496
Published on: 10/12/2021 12:00:00 AM UTC
Last Modified on: 11/23/2021 09:46:00 PM UTC
Certain versions of Jasperreports Server from Tibco contain the following vulnerability:
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to interfere with XML processing in the affected component. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.2.1 and below, TIBCO JasperReports Server: versions 7.5.0 and 7.5.1, TIBCO JasperReports Server: version 7.8.0, TIBCO JasperReports Server: version 7.9.0, TIBCO JasperReports Server - Community Edition: versions 7.8.0 and below, TIBCO JasperReports Server - Developer Edition: versions 7.9.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and below, and TIBCO JasperReports Server for Microsoft Azure: version 7.8.0.
- CVE-2021-35496 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Advisory | TIBCO Software | web.archive.org text/html Inactive LinkNot Archived |
![]() |
TIBCO Security Advisory: October 12, 2021 - TIBCO JasperReports Server - 2021-35496 | TIBCO Software | www.tibco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Jasperreports Server | 7.5.0 | All | All | All |
Application | Tibco | Jasperreports Server | 7.5.1 | All | All | All |
Application | Tibco | Jasperreports Server | 7.8.0 | All | All | All |
Application | Tibco | Jasperreports Server | 7.9.0 | All | All | All |
Application | Tibco | Jasperreports Server | All | All | All | All |
Application | Tibco | Jasperreports Server | All | All | All | All |
Application | Tibco | Jasperreports Server | All | All | All | All |
Application | Tibco | Jasperreports Server | All | All | All | All |
Application | Tibco | Jasperreports Server | All | All | All | All |
Application | Tibco | Jasperreports Server | All | All | All | All |
- cpe:2.3:a:tibco:jasperreports_server:7.5.0:*:*:*:*:-:*:*:
- cpe:2.3:a:tibco:jasperreports_server:7.5.1:*:*:*:*:-:*:*:
- cpe:2.3:a:tibco:jasperreports_server:7.8.0:*:*:*:*:-:*:*:
- cpe:2.3:a:tibco:jasperreports_server:7.9.0:*:*:*:*:-:*:*:
- cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:-:*:*:
- cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:microsoft_azure:*:*:
- cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:community:*:*:*:
- cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:*:
- cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:aws_marketplace:*:*:
- cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:developer:*:*:*:
Discovery Credit
TIBCO would like to extend its appreciation to Dr. Florian Hauser, CODE WHITE GmbH for discovery of this vulnerability.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-35496 : The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperRe… twitter.com/i/web/status/1… | 2021-10-12 17:41:30 |