#VU28111 Improper access control in TIBCO products - CVE-2020-9409
Published: May 20, 2020
TIBCO JasperReports Server
TIBCO JasperReports Server for AWS Marketplace
TIBCO JasperReports Server for ActiveMatrix BPM
JasperSoft
TIBCO
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in "administrative UI" component. A remote attacker can obtain a "superuser" permission, bypass implemented security restrictions and gain unauthorized access to the application, leading to arbitrary code execution.