Path traversal in JasperSoft products - CVE-2022-22771

 

Path traversal in JasperSoft products - CVE-2022-22771

Published: March 16, 2022


Vulnerability identifier: #VU61397
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22771
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the Server component. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

TIBCO JasperReports Library
TIBCO JasperReports Library for ActiveMatrix BPM
TIBCO JasperReports Server
TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
TIBCO JasperReports Server for Microsoft Azure

How to mitigate CVE-2022-22771

Install update from vendor's website.

TIBCO JasperReports Library - update to 7.9.2
TIBCO JasperReports Library for ActiveMatrix BPM - update to 7.9.2
TIBCO JasperReports Server - update to 7.9.2
TIBCO JasperReports Server for AWS Marketplace - update to 7.9.2
TIBCO JasperReports Server for ActiveMatrix BPM - update to 7.9.2
TIBCO JasperReports Server for Microsoft Azure - update to 7.9.2

External References

Related Security Bulletins