Jaspersoft
Vendor:
First CVE: Jun 29, 2017 · Active for 9 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
20.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Jaspersoft over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2017
9 years ago
Most Recent CVE
Mar 7, 2019
2,698 days ago
CVE Severity & Scoring
Jaspersoft10 CVEs
40%
40%
20%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None3 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18809MEDIUM The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix | Mar 7, 2019 | 6.5 | 94 | YES | YES |
CVE-2018-5430HIGH The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspe | Apr 17, 2018 | 8.8 | 91 | YES | YES |
CVE-2018-18815CRITICAL The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jas | Mar 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2017-5533CRITICAL A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jasp | Nov 15, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-5528HIGH Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attack | Jun 29, 2017 | 8.8 | 28 | NO | NO |
CVE-2018-5429HIGH A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for | Apr 17, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-18808HIGH The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, | Mar 7, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-18816MEDIUM The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO J | Mar 7, 2019 | 5.4 | 21 | NO | NO |
CVE-2017-5532MEDIUM A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO | Nov 15, 2017 | 5.4 | 20 | NO | NO |
CVE-2018-5431MEDIUM The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TI | Apr 17, 2018 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
2 CVEs
20.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Jaspersoft
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.4.0 | 1 | 9.8 | 2.0% | 0 | 0 |