
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2022-41561) affects the JNDI Data Sources component of TIBCO JasperReports Server and its various editions (Community, Developer, AWS Marketplace, and Microsoft Azure versions). The vulnerability was disclosed on December 13, 2022, impacting versions 8.0.2 and below, as well as version 8.1.0 across all editions (NIST NVD).
This vulnerability allows privileged/administrative attackers with network access to execute Remote Code Execution (RCE) and obtain a reverse shell on the affected system. The vulnerability has been assigned a CVSS v3.1 base score of 7.2 (HIGH) by NIST NVD with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, while TIBCO assessed it with a more severe CVSS score of 9.1 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H (NIST NVD).
The vulnerability enables attackers with administrative privileges to execute remote code and establish a reverse shell connection to the affected system, potentially leading to complete system compromise with high impacts on confidentiality, integrity, and availability (NIST NVD).
The vulnerability is described as 'easily exploitable' and requires network access along with privileged/administrative access to the system. The attack complexity is rated as Low (AC:L), indicating minimal technical expertise is needed to exploit the vulnerability once administrative access is obtained (NIST NVD).
TIBCO has addressed this vulnerability in subsequent releases. Users are advised to upgrade to versions newer than those affected (8.0.2 and 8.1.0) across all editions of JasperReports Server (TIBCO Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."