Back

CVE-2018-18815

CRITICAL

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Published: Mar 7, 2019 Modified: Jun 17, 2026
CWE-863

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (9)

Vendor Product Version
tibco jasperreports_server *
tibco jasperreports_server *
tibco jasperreports_server 6.4.0
tibco jasperreports_server 6.4.1
tibco jasperreports_server 6.4.2
tibco jasperreports_server 6.4.3
tibco jasperreports_server 7.1.0
tibco jaspersoft *
tibco jaspersoft_reporting_and_analytics *

GitHub Security Advisory GHSA-x2m2-4jfp-mm86

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 3.13%

Top 13% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub