S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-18809 Scanner

CVE-2018-18809 scanner - Directory Traversal vulnerability in TIBCO JasperReports Library

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-18809
6.5
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient.

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
TIBCO JasperReports Libraryby TIBCO Software Inc.
unspecified
TIBCO JasperReports Library Community Editionby TIBCO Software Inc.
unspecified
TIBCO JasperReports Library for ActiveMatrix BPMby TIBCO Software Inc.
unspecified
TIBCO JasperReports Serverby TIBCO Software Inc.
unspecified
Updated Aug 21, 2026View on NVD →
Detail

TIBCO JasperReports Library is a highly popular reporting and analytics tool used by enterprises and businesses for creating and deploying reports, charts, and dashboards. This product is widely used for creating data-driven reports that can be embedded into web pages or accessed through various web-based applications. TIBCO JasperReports Library is known for its ease of use, data visualization capabilities, and extensibility. 

Recently, a directory-traversal vulnerability has been found in the TIBCO JasperReports Library. The vulnerability code is CVE-2018-18809, and it affects multiple TIBCO Software products, including TIBCO JasperReports Library, TIBCO JasperReports Server, and TIBCO Jaspersoft Reporting and Analytics for AWS. This vulnerability can potentially allow hackers to access files and directories beyond the web server's root directory and leak sensitive information.

If exploited, this vulnerability can have severe repercussions for the impacted organization. Attackers can gain access to confidential data, such as login credentials, financial information, and other sensitive data, leading to identity theft, financial loss, and reputational damage. This vulnerability can also allow an attacker to execute arbitrary code on the target system, compromise the server's integrity, and disrupt critical business functions.

Thanks to the pro features of s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets. The platform offers a vast database of known vulnerabilities, along with customized alerts and reports that can help you stay up-to-date with the latest security threats. By leveraging s4e.io, you can gain peace of mind and ensure that your organization's digital assets are secure from emerging cyber threats.

 

REFERENCES

Solution Advice

To protect against the CVE-2018-18809 vulnerability, it is recommended to take the following precautions:

  • Upgrade to the latest version of TIBCO JasperReports Library, TIBCO JasperReports Server, and TIBCO Jaspersoft Reporting and Analytics for AWS.
  • Implement access controls and permissions to restrict unauthorized access to sensitive files and directories.
  • Apply regular security patches and updates to keep software and systems secure.
  • Use firewalls and intrusion detection/prevention systems to detect and block malicious traffic.
  • Utilize a robust, multi-layered security solution that includes anti-virus, anti-malware, and anti-phishing tools.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-18809 scanner - Directory Traversal vulnerability in TIBCO JasperReports Library | S4E