← Vulnerability feed

Vulnerability record · CVE-2020-9409 · published 20 May 2020

CVE-2020-9409: Tibco jasperreports server incorrect default permissions vulnerability

Tibco · Jasperreports Server

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.

9.8 CVSS 3.1 Critical EPSS 3.4% · top 11.5% CWE-276 · Incorrect default permissions
9.8CVSS 3.1 base score, v2 10.0
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-5430TIBCO JasperReports Server path traversal allows authenticated file readThe Spring web flows in TIBCO JasperReports Server and related Jaspersoft products are vulnerable to path traversal, letting any authenticated user r…KEVEPSS 49%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed6.5CVE-2018-18809TIBCO JasperReports directory traversal exposes host filesThe default server implementation in multiple TIBCO JasperReports Library, JasperReports Server, and Jaspersoft products contains a directory-travers…KEVEPSS 79%analysed9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-12419Apache cxf incorrect authorization vulnerabilityApache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…EPSS 14%9.8CVE-2019-13990Softwareag quartz xml external entity (xxe) vulnerabilityinitDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.EPSS 16%9.8CVE-2018-18815Tibco jasperreports server incorrect authorization vulnerabilityThe REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server …EPSS 3.1%9.8CVE-2018-8013Apache batik deserialization of untrusted data vulnerabilityIn Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2020-9409), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.