Path traversal in JasperSoft products - CVE-2022-22771
Published: March 16, 2022
Vulnerability identifier: #VU61397
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22771
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Server component. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
TIBCO JasperReports Library
TIBCO JasperReports Library for ActiveMatrix BPM
TIBCO JasperReports Server
TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
TIBCO JasperReports Server for Microsoft Azure
TIBCO JasperReports Library for ActiveMatrix BPM
TIBCO JasperReports Server
TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
TIBCO JasperReports Server for Microsoft Azure
How to mitigate CVE-2022-22771
Install update from vendor's website.
TIBCO JasperReports Library - update to 7.9.2
TIBCO JasperReports Library for ActiveMatrix BPM - update to 7.9.2
TIBCO JasperReports Server - update to 7.9.2
TIBCO JasperReports Server for AWS Marketplace - update to 7.9.2
TIBCO JasperReports Server for ActiveMatrix BPM - update to 7.9.2
TIBCO JasperReports Server for Microsoft Azure - update to 7.9.2
TIBCO JasperReports Library for ActiveMatrix BPM - update to 7.9.2
TIBCO JasperReports Server - update to 7.9.2
TIBCO JasperReports Server for AWS Marketplace - update to 7.9.2
TIBCO JasperReports Server for ActiveMatrix BPM - update to 7.9.2
TIBCO JasperReports Server for Microsoft Azure - update to 7.9.2