Jasperreports Server
Vendor:
First CVE: Jun 29, 2017 · Active for 9 years
23
Total CVEs
More Total CVEs than 96% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
8.7%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Jasperreports Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2017
9 years ago
Most Recent CVE
Apr 17, 2024
831 days ago
CVE Severity & Scoring
Jasperreports Server23 CVEs
35%
52%
13%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None14 (60.9%)
Unknown0 (0.0%)
Required9 (39.1%)
Privileges Required
Low15 (65.2%)
High3 (13.0%)
None5 (21.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18809MEDIUM The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix | Mar 7, 2019 | 6.5 | 94 | YES | YES |
CVE-2018-5430HIGH The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspe | Apr 17, 2018 | 8.8 | 91 | YES | YES |
CVE-2020-9409CRITICAL The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix | May 20, 2020 | 9.8 | 32 | NO | NO |
CVE-2018-18815CRITICAL The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jas | Mar 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2020-9410HIGH The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperRepor | May 20, 2020 | 8.8 | 30 | NO | NO |
CVE-2017-5533CRITICAL A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jasp | Nov 15, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-5528HIGH Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attack | Jun 29, 2017 | 8.8 | 28 | NO | NO |
CVE-2022-22771HIGH The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server | Mar 15, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-35495HIGH The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO Ja | Oct 12, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-5429HIGH A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for | Apr 17, 2018 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
2 CVEs
8.7% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
1 CVE
4.3% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Jasperreports Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1.0 | 3 | 7.0 | 1.0% | 0 | 0 |
| 7.9.1 | 1 | 8.8 | 2.1% | 0 | 0 |
| 7.9.0 | 4 | 8.1 | 1.5% | 0 | 0 |
| 7.8.0 | 3 | 7.2 | 0.6% | 0 | 0 |
| 7.5.1 | 3 | 7.2 | 0.6% | 0 | 0 |
| 7.5.0 | 4 | 7.6 | 1.7% | 0 | 0 |
| 7.2.0 | 1 | 8.8 | 5.1% | 0 | 0 |
| 7.1.0 | 4 | 7.3 | 21.3% | 1 | 1 |
| 6.4.3 | 4 | 7.6 | 1.8% | 0 | 0 |
| 6.4.2 | 7 | 7.6 | 8.3% | 1 | 1 |
| 6.4.1 | 4 | 7.6 | 1.8% | 0 | 0 |
| 6.4.0 | 9 | 8.0 | 5.9% | 1 | 1 |
| 6.3.3 | 3 | 7.7 | 17.0% | 1 | 1 |
| 6.3.2 | 4 | 7.1 | 12.9% | 1 | 1 |
| 6.3.1 | 1 | 5.4 | 0.7% | 0 | 0 |
| 6.3.0 | 6 | 7.3 | 8.9% | 1 | 1 |
| 6.2.1 | 2 | 7.7 | 0.9% | 0 | 0 |
| 6.2.0 | 2 | 7.7 | 0.9% | 0 | 0 |