CVE-2022-41561
TIBCO JasperReports Server vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2022-41561) affects the JNDI Data Sources component of TIBCO JasperReports Server and its various editions (Community, Developer, AWS Marketplace, and Microsoft Azure versions). The vulnerability was disclosed on December 13, 2022, impacting versions 8.0.2 and below, as well as version 8.1.0 across all editions (NIST NVD).

Technical details

This vulnerability allows privileged/administrative attackers with network access to execute Remote Code Execution (RCE) and obtain a reverse shell on the affected system. The vulnerability has been assigned a CVSS v3.1 base score of 7.2 (HIGH) by NIST NVD with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, while TIBCO assessed it with a more severe CVSS score of 9.1 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H (NIST NVD).

Impact

The vulnerability enables attackers with administrative privileges to execute remote code and establish a reverse shell connection to the affected system, potentially leading to complete system compromise with high impacts on confidentiality, integrity, and availability (NIST NVD).

Exploitability

The vulnerability is described as 'easily exploitable' and requires network access along with privileged/administrative access to the system. The attack complexity is rated as Low (AC:L), indicating minimal technical expertise is needed to exploit the vulnerability once administrative access is obtained (NIST NVD).

Mitigation and workarounds

TIBCO has addressed this vulnerability in subsequent releases. Users are advised to upgrade to versions newer than those affected (8.0.2 and 8.1.0) across all editions of JasperReports Server (TIBCO Advisory).

Additional resources


SourceThis report was generated using AI

Related TIBCO JasperReports Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-3325HIGH8.6
  • TIBCO JasperReports Server logoTIBCO JasperReports Server
  • jasperreports
NoYesJul 10, 2024
CVE-2022-41562HIGH8.4
  • TIBCO JasperReports Server logoTIBCO JasperReports Server
  • jasperreports
NoYesDec 13, 2022
CVE-2024-3323HIGH8.3
  • TIBCO JasperReports Server logoTIBCO JasperReports Server
  • cpe:2.3:a:tibco:jasperreports_server
NoYesApr 17, 2024
CVE-2022-41561HIGH7.2
  • TIBCO JasperReports Server logoTIBCO JasperReports Server
  • jasperreports
NoYesDec 13, 2022
CVE-2022-41563MEDIUM5.4
  • TIBCO JasperReports Server logoTIBCO JasperReports Server
  • cpe:2.3:a:tibco:jasperreports_server
NoYesDec 13, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management