Vulnerability Details CVE-2019-8986
The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.6%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 4.0
Products affected by CVE-2019-8986
-
cpe:2.3:a:tibco:jasperreports_server:-
-
cpe:2.3:a:tibco:jasperreports_server:6.1.1
-
cpe:2.3:a:tibco:jasperreports_server:6.1.2
-
cpe:2.3:a:tibco:jasperreports_server:6.2.0
-
cpe:2.3:a:tibco:jasperreports_server:6.2.1
-
cpe:2.3:a:tibco:jasperreports_server:6.2.3
-
cpe:2.3:a:tibco:jasperreports_server:6.2.4
-
cpe:2.3:a:tibco:jasperreports_server:6.2.5
-
cpe:2.3:a:tibco:jasperreports_server:6.3.0
-
cpe:2.3:a:tibco:jasperreports_server:6.3.1
-
cpe:2.3:a:tibco:jasperreports_server:6.3.2
-
cpe:2.3:a:tibco:jasperreports_server:6.3.3
-
cpe:2.3:a:tibco:jasperreports_server:6.3.4
-
cpe:2.3:a:tibco:jasperreports_server:6.4.0
-
cpe:2.3:a:tibco:jasperreports_server:6.4.1
-
cpe:2.3:a:tibco:jasperreports_server:6.4.2
-
cpe:2.3:a:tibco:jasperreports_server:6.4.3