QID 731140

Date Published: 2024-02-12

QID 731140: TIBCO JasperReports Server Directory Traversal Vulnerability (CVE-2022-22771)

JasperReports is an open-source reporting engine that provides the ability to deliver rich content onto the printer, the screen, or into various formats such as PDF, HTML, XLS, RTF, ODT, CSV, TXT, and XML files.

CVE-2022-22771: This vulnerability contains a directory-traversal vulnerability that may theoretically allow web server users to access the contents of the host system.

Affected Products:
TIBCO JasperReports Server versions 7.9.0 and 7.9.1

QID Detection Logic:(unauthenticated)
It checks for vulnerable versions of the TIBCO JasperReports Server.

Successful execution of this vulnerability may allow web server users to access the contents of the host system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to follow the TIBCO Security Advisory:_CVE-2022-22771 for remediation instructions.

    CVEs related to QID 731140

    Software Advisories
    Advisory ID Software Component Link
    TIBCO Security Advisory URL Logo www.tibco.com/support/advisories/2022/03/tibco-security-advisory-march-15-2022-tibco-jasperreports-library-2022-22771