Known vulnerabilities in TIBCO JasperReports Server - Community Edition
Vendor:
TIBCO
Software CPE:
cpe:2.3:a:tibco:tibco_jasperreports_server_-_community_edition:*:*:*:*:*:*:*:*
Website:
https://www.tibco.com/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU70351 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-41562 |
CWE-79 | Low | 8.1.1 | 15.12.2022 |
SB2022121503 |
||
| #VU70350 - Improper Control of Generation of Code ('Code Injection') CVE-2022-41561 |
CWE-94 | Low | 8.1.1 | 15.12.2022 |
SB2022121503 |
||
| #VU63354 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-22773 |
CWE-79 | Low | 8.0.2 | 18.05.2022 |
SB2022051803 |
||
| #VU57327 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-35496 |
CWE-611 | Medium | 7.8.1 | 13.10.2021 |
SB2021101309 |
||
| #VU57326 - Improper Access Control CVE-2021-35495 |
CWE-284 | Medium | 7.8.1 | 13.10.2021 |
SB2021101309 |
||
| #VU57325 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2021-35494 |
CWE-362 | Medium | 7.8.1 | 13.10.2021 |
SB2021101309 |