← Vulnerability feed

Vulnerability record · CVE-2018-5430 · published 17 April 2018

CVE-2018-5430: TIBCO JasperReports Server path traversal allows authenticated file read

Tibco · Jasperreports Server

The Spring web flows in TIBCO JasperReports Server and related Jaspersoft products are vulnerable to path traversal, letting any authenticated user read arbitrary files from the web application, including key configuration files. This exposes sensitive data such as credentials and configuration that can enable further compromise.

8.8 CVSS 3.1 High CISA KEV since 29 Dec 2022 EPSS 49% · top 1.2% CWE-22 · Path traversalCWE-200 · Information exposure
8.8CVSS 3.1 base score, v2 4.0
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8, active exploitation per CISA KEV, public exploit code, and very high EPSS make this a high-priority patching target despite requiring authentication.

What it is

The Spring web flows in TIBCO JasperReports Server and related Jaspersoft products are vulnerable to path traversal, letting any authenticated user read arbitrary files from the web application, including key configuration files. This exposes sensitive data such as credentials and configuration that can enable further compromise.

Impact

An attacker with a valid low-privileged account gains read-only access to application files and configuration, potentially harvesting secrets for lateral movement or privilege escalation.

Attack surface

Reachable over the network through the Spring web flows; authentication is required (PR:L) and no user interaction is needed (UI:N).

Exploitation

CISA KEV lists it as exploited, public exploit code exists (Exploit-DB 44623, Rhino Security Labs), and EPSS is 0.4963 (98.8th percentile).

What to do

  • Apply the vendor updates referenced in the TIBCO security advisory for all affected JasperReports Server and Jaspersoft products.
  • If immediate patching is not possible, restrict network access to the JasperReports Server web interface to trusted users and networks.
  • Audit and rotate any credentials or secrets stored in configuration files that may have been exposed.
  • Enforce least privilege and monitor authenticated accounts for unusual file access patterns.

Detection

  • Monitor web logs for path traversal patterns (e.g., ../, encoded variants) in requests to Spring web flow endpoints.
  • Alert on authenticated users accessing configuration or non-public files outside normal reporting paths.
  • Review file access logs for reads of sensitive configuration files by application service accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-5430 to the Known Exploited Vulnerabilities catalog on 29 December 2022 as "TIBCO JasperReports Server Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 January 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5430 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2018-18809TIBCO JasperReports directory traversal exposes host filesThe default server implementation in multiple TIBCO JasperReports Library, JasperReports Server, and Jaspersoft products contains a directory-travers…KEVEPSS 79%analysed9.8CVE-2020-9409Tibco jasperreports server incorrect default permissions vulnerabilityThe administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO Jasper…EPSS 3.4%9.8CVE-2018-18815Tibco jasperreports server incorrect authorization vulnerabilityThe REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server …EPSS 3.1%9.8CVE-2017-5533Tibco jasperreports server vulnerabilityA vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server f…EPSS 2.0%8.8CVE-2022-22771Tibco jasperreports library path traversal vulnerabilityThe Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Serv…EPSS 2.5%8.8CVE-2021-35495Tibco jasperreports server vulnerabilityThe Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO…EPSS 0.83%8.8CVE-2020-9410Tibco jasperreports library cross-site scripting vulnerabilityThe report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperRe…EPSS 5.2%8.8CVE-2018-5429Tibco jasperreports server vulnerabilityA vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, …EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2018-5430), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.