Cross-site scripting in JasperSoft products - CVE-2020-9410

 

Cross-site scripting in JasperSoft products - CVE-2020-9410

Published: May 20, 2020


Vulnerability identifier: #VU28112
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-9410
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the "report generator" component. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
TIBCO JasperReports Library for ActiveMatrix BPM
TIBCO JasperReports Library
TIBCO JasperReports Server
Oracle Retail Order Broker

How to mitigate CVE-2020-9410

Install updates from vendor's website.

TIBCO JasperReports Server for AWS Marketplace - update to 7.5.1
TIBCO JasperReports Library for ActiveMatrix BPM - update to 7.1.3
TIBCO JasperReports Server for ActiveMatrix BPM - update to 7.1.3
TIBCO JasperReports Library - addressed in versions 7.1.3, 7.2.2, 7.3.1, 7.5.1
TIBCO JasperReports Server - addressed in versions 7.1.3, 7.2.1, 7.5.1

External References

Related Security Bulletins