#VU57327 XML External Entity injection in TIBCO products - CVE-2021-35496
Published: October 13, 2021
TIBCO JasperReports Server
TIBCO JasperReports Server - Community Edition
TIBCO JasperReports Server - Developer Edition
TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
TIBCO JasperReports Server for Microsoft Azure
JasperSoft
TIBCO
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input in the XMLA Connections component. A remote authenticated attacker can gain unauthorized read access, as well as unauthorized update, insert or delete access to a subset of the affected systems data and cause a denial of servie (DoS) condition.