Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18808

Опубликовано: 07 мар. 2019
Источник: nvd
CVSS3: 8.8
CVSS3: 7.5
CVSS2: 8.5
EPSS Низкий

Описание

The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability that may allow any users with domain save privileges to gain superuser privileges. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*
Версия до 6.3.4 (включая)
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:*
Версия до 6.4.3 (включая)
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:community:*:*:*
Версия до 7.1.0 (включая)
cpe:2.3:a:tibco:jasperreports_server:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:7.1.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:tibco:jaspersoft:*:*:*:*:*:aws_with_multi-tenancy:*:*
Версия до 7.1.0 (включая)
cpe:2.3:a:tibco:jaspersoft_reporting_and_analytics:*:*:*:*:*:aws:*:*
Версия до 7.1.0 (включая)

EPSS

Процентиль: 57%
0.00354
Низкий

8.8 High

CVSS3

7.5 High

CVSS3

8.5 High

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability that may allow any users with domain save privileges to gain superuser privileges. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

EPSS

Процентиль: 57%
0.00354
Низкий

8.8 High

CVSS3

7.5 High

CVSS3

8.5 High

CVSS2

Дефекты

CWE-362