XML External Entity injection in TIBCO products - CVE-2021-35496
Published: October 13, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input in the XMLA Connections component. A remote authenticated attacker can gain unauthorized read access, as well as unauthorized update, insert or delete access to a subset of the affected systems data and cause a denial of servie (DoS) condition.
Affected software
TIBCO JasperReports Server - Community Edition
TIBCO JasperReports Server for Microsoft Azure
TIBCO JasperReports Server - Developer Edition
TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
How to mitigate CVE-2021-35496
TIBCO JasperReports Server - Community Edition - update to 7.8.1
TIBCO JasperReports Server for Microsoft Azure - update to 7.9.1
TIBCO JasperReports Server - Developer Edition - update to 7.9.1
TIBCO JasperReports Server for AWS Marketplace - update to 7.9.1
TIBCO JasperReports Server for ActiveMatrix BPM - update to 7.9.1