vendor:
JasperReports
by:
7.7
CVSS
HIGH
Authenticated File Read and Inclusion
22
CWE
Product Name: JasperReports
Affected Version From: <=6.2.4, 6.3.0, 6.3.2-3, 6.4.0, 6.4.2, CE/ActiveMatrix BPM and Jaspersoft AWS with Multi-Tenancy/Reporting and Analytics for AWS <=6.4.2
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Authenticated File Read and Inclusion Vulnerability in TIBCO’s JasperReports
TIBCO’s JasperReports (<=6.2.4, 6.3.0, 6.3.2-3, 6.4.0, 6.4.2, CE/ActiveMatrix BPM and Jaspersoft AWS with Multi-Tenancy/Reporting and Analytics for AWS <=6.4.2) is vulnerable to an authenticated file read and inclusion vulnerability by means of directory traversal. It is possible for an attacker, regardless of user permissions, to access or include files from within the filesystem hosting the application.