LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-18809: TIBCO JasperReports Library Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 29, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 19, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-18809 to its Known Exploited Vulnerabilities catalog on Dec 29, 2022, with a federal patch deadline of Jan 19, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

CVE-2018-18809 is a directory-traversal vulnerability in the TIBCO JasperReports Library. It can allow web server users to reach contents of the host system beyond the intended application paths. For IT and security teams, this matters because JasperReports is commonly embedded in reporting and business-intelligence deployments; successful abuse can expose configuration files, credentials, or other sensitive data on the server, increasing the chance of further compromise.

Public detail is limited to the CWE-22 classification and the CISA description. Confirm exact product editions, fixed versions, and any prerequisites against the vendor advisory before acting.

How it works

The flaw belongs to CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In products of this class, user-supplied input that influences file or resource paths is not sufficiently sanitized. An attacker who can interact with the web-facing components of JasperReports may craft path sequences that escape the application’s intended directory and read arbitrary files accessible to the process identity.

Abuse typically requires only the ability to send requests as a web server user; no additional authentication details are stated in the available summary. The result is unauthorized disclosure of host-system contents rather than remote code execution. Exact request formats or parameters are not provided here and must be verified in the vendor advisory.

Am I affected? How to find it in your systems

TIBCO JasperReports Library is frequently deployed as part of reporting servers, embedded analytics engines, or custom Java applications that generate PDF, Excel, or HTML reports. It commonly runs on application servers or containers that expose HTTP endpoints.

How to remediate

Apply the vendor-supplied updates for the TIBCO JasperReports Library exactly as instructed in the official advisory. CISA’s required action is simply to apply those updates. After patching, restart affected services and re-verify the library version.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls that limit both reachability and impact.

If your data may have been exposed

Actively exploited directory-traversal vulnerabilities can lead to data breaches when sensitive files are retrieved. Although ransomware use is not documented for this CVE, treat any confirmed exploitation as a potential incident: isolate the host, preserve logs, and perform forensic review of accessed files. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTIBCO · JasperReports
WeaknessCWE-22
Added to CISA KEVDec 29, 2022
Federal patch deadlineJan 19, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities