CVE Published: 20/05/2020 |
CVE Updated: 17/09/2024 |
CVE Year: 2020 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO JasperReports Server Status : PUBLISHED
CVE-2020-9409 Description
The administrative UI component of TIBCO Software Inc.\'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.\'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE Name: The impact of this vulnerability includes the possibility that an unauthenticated user obtains JasperReports Server "superuser" permission, and further might be able to execute arbitrary code with the system account that started the affected component. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)