Technical Severity
CRITICALCVSS v3.1 Metrics
9.9
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitation Likelihood
EPSS Prediction
93.91
%
Predictive Probability
Percentile Rank
99.9
th
Documented as more likely to be exploited than 99.9% of known CVEs.
Detection Date
Dec 29, 2022
Remediation Due
Jan 19, 2023
CISA Catalog Active
Threat Analysis
TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
Remediation Directive
Apply updates per vendor instructions.
External Intelligence
https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809
https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809
NVD
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2018-18809