VYPR
Medium severity4.1NVD Advisory· Published Jun 29, 2017· Updated May 13, 2026

CVE-2017-5529

CVE-2017-5529

Description

JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO JasperReports Professional (versions 6.2.1 and below, and 6.3.0), TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.3.0 and below), TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.3.0 and below), and TIBCO Jaspersoft Studio for ActiveMatrix BPM (versions 6.2.0 and below).

Affected products

22
  • cpe:2.3:a:tibco:jasperreports_library_community_edition:*:*:*:*:*:*:*:*
    Range: <=6.4.0
  • cpe:2.3:a:tibco:jasperreports_library_for_activematrix_bpm:*:*:*:*:*:*:*:*
    Range: <=6.2.0
  • cpe:2.3:a:tibco:jasperreports_professional:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tibco:jasperreports_professional:*:*:*:*:*:*:*:*range: <=6.2.1
    • cpe:2.3:a:tibco:jasperreports_professional:6.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*range: <=6.1.1
    • cpe:2.3:a:tibco:jasperreports_server:6.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:jasperreports_server:6.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:jasperreports_server:6.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:jasperreports_server_community_edition:*:*:*:*:*:*:*:*
    Range: <=6.3.0
  • cpe:2.3:a:tibco:jasperreports_server_for_activematrix_bpm:*:*:*:*:*:*:*:*
    Range: <=6.2.0
  • cpe:2.3:a:tibco:jaspersoft_for_aws_with_multi-tenancy:*:*:*:*:*:*:*:*
    Range: <=6.3.0
  • cpe:2.3:a:tibco:jaspersoft_reporting_and_analytics_for_aws:*:*:*:*:*:*:*:*
    Range: <=6.3.0
  • cpe:2.3:a:tibco:jaspersoft_studio_for_activematrix_bpm:*:*:*:*:*:*:*:*
    Range: <=6.2.0
  • TIBCO Software Inc./TIBCO JasperReports Library Community Editionv5
    Range: 6.4.0
  • TIBCO Software Inc./TIBCO JasperReports Library for ActiveMatrix BPMv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO JasperReports Professionalv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO JasperReports Serverv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO JasperReports Server Community Editionv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO JasperReports Server for ActiveMatrix BPMv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO Jaspersoft for AWS with Multi-Tenancyv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO Jaspersoft Reporting and Analytics for AWSv5
    Range: unspecified
  • TIBCO Software Inc./TIBCO Jaspersoft Studio for ActiveMatrix BPMv5
    Range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.