Vulnerability record · CVE-2018-18809 · published 7 March 2019
CVE-2018-18809: TIBCO JasperReports directory traversal exposes host files
Tibco · Jasperreports Library
The default server implementation in multiple TIBCO JasperReports Library, JasperReports Server, and Jaspersoft products contains a directory-traversal flaw (CWE-22) that lets web server users read files from the host system. It affects a wide range of releases across the JasperReports and Jaspersoft product lines, so unpatched deployments are broadly exposed.
Description
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCISA KEV listing, very high EPSS score, and public exploit references indicate active exploitation, though the CVSS score is medium and impact is confidentiality-only.
What it is
The default server implementation in multiple TIBCO JasperReports Library, JasperReports Server, and Jaspersoft products contains a directory-traversal flaw (CWE-22) that lets web server users read files from the host system. It affects a wide range of releases across the JasperReports and Jaspersoft product lines, so unpatched deployments are broadly exposed.
Impact
An attacker with a low-privileged account can read arbitrary files on the host, potentially exposing configuration, credentials, and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via the web server (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). The traversal is triggered through normal web requests to the affected server implementation.
Exploitation
The vulnerability is listed in CISA KEV (added 2022-12-29) and has a very high EPSS probability (0.79, ~99.6th percentile), and multiple references are tagged as exploits, indicating active exploitation and public exploit availability.
What to do
- Apply the vendor updates referenced in the TIBCO security advisory for CVE-2018-18809.
- Upgrade JasperReports Library, JasperReports Server, and Jaspersoft products to versions beyond the affected ranges listed in the advisory.
- Restrict network access to JasperReports/Jaspersoft servers to trusted users and networks.
- Enforce least privilege on service accounts and file system permissions to limit what a traversal can read.
- Monitor for and block path traversal patterns in requests to the reporting server.
Detection
- Inspect web server and application logs for requests containing ../ or encoded traversal sequences (e.g., %2e%2e%2f) targeting JasperReports endpoints.
- Alert on unusual file access by the JasperReports service account outside expected directories.
- Monitor for known exploit request patterns against JasperReports/Jaspersoft URLs.
- Correlate outbound or file-read activity from the reporting server with suspicious client IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-18809 to the Known Exploited Vulnerabilities catalog on 29 December 2022 as "TIBCO JasperReports Library Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 January 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-18809 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-18809), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.