CVE Vulnerabilities

CVE-2019-8986

Published: Mar 07, 2019 | Modified: Jan 01, 2022
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The SOAP API component vulnerability of TIBCO Software Inc.s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3.

Affected Software

Name Vendor Start Version End Version
Jasperreports_server Tibco * 6.3.4 (including)
Jasperreports_server Tibco * 6.4.3 (including)
Jasperreports_server Tibco 6.4.0 (including) 6.4.0 (including)
Jasperreports_server Tibco 6.4.1 (including) 6.4.1 (including)
Jasperreports_server Tibco 6.4.2 (including) 6.4.2 (including)
Jasperreports_server Tibco 6.4.3 (including) 6.4.3 (including)

References