QID 731139

Date Published: 2024-02-08

QID 731139: TIBCO JasperReports Server Reflected Cross-Site Scripting (XSS) Vulnerability (CVE-2022-22773)

JasperReports is an open-source reporting engine that provides the ability to deliver rich content onto the printer, the screen, or into various formats such as PDF, HTML, XLS, RTF, ODT, CSV, TXT, and XML files.

CVE-2022-22773: This vulnerability contains difficult-to-exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low-privileged attacker with network access to execute scripts targeting the affected system or the victim's local system.

Affected Products:
TIBCO JasperReports Server versions 8.0.1 and below.

QID Detection Logic:(unauthenticated)
It checks for vulnerable versions of the TIBCO JasperReports Server.

Note: The QID is marked as potential as the workaround is present for this vulnerability and it is not possible to detect the applied workaround in unauthenticated detection.

Successful execution of this vulnerability will allow a low-privileged attacker with network access to execute scripts targeting the affected system or the victim's local system..

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to follow the TIBCO Security Advisory:_CVE-2022-22773 Workaround:
    If an upgrade is not possible, browser rendering of the rest-api responses in html and xml format can be disabled by restricting content-type headers.

    CVEs related to QID 731139

    Software Advisories
    Advisory ID Software Component Link
    TIBCO Security Advisory URL Logo www.tibco.com/support/advisories/2022/05/tibco-security-advisory-may-17-2022-tibco-jasperreports-server-cve-2022-22773