Improper access control in TIBCO JasperReports Server - CVE-2018-18815
Published: March 6, 2019
TIBCO JasperReports Server
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions within the doGet method of the ResourceForwardingServlet. A remote unauthenticated attacker can request the vulnerable URL and gain unauthorized access to sensitive information.