Improper access control in JasperSoft products - CVE-2020-9409
Published: May 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in "administrative UI" component. A remote attacker can obtain a "superuser" permission, bypass implemented security restrictions and gain unauthorized access to the application, leading to arbitrary code execution.
Affected software
TIBCO JasperReports Server for ActiveMatrix BPM
TIBCO JasperReports Server
How to mitigate CVE-2020-9409
TIBCO JasperReports Server for ActiveMatrix BPM - update to 7.1.3
TIBCO JasperReports Server - update to 7.1.3