Vulnerabilities > Tibco > Jasperreports Library > 7.5.0

DATE CVE VULNERABILITY TITLE RISK
2020-05-20 CVE-2020-9410 Cross-site Scripting vulnerability in multiple products
The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an attacker to exploit HTML injection to gain full control of a web interface containing the output of the report generator component with the privileges of any user that views the affected report(s).
network
low complexity
tibco oracle CWE-79
8.8