Site icon TheCyberThrone

CISA adds JasperReports Flaws to Known Exploited Catalog

Advertisements

The US CISA has added TIBCO Software’s JasperReports vulnerabilities, to its Known Exploited Vulnerabilities catalog.

TIBCO JasperReports is an open-source Java reporting tool for creating and managing reports and dashboards and it has vulnerabilities tracked as CVE-2018-5430 with a CVSS score of 7.7 and CVE-2018-18809 with a CVSS score of 9.9.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies must address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Advertisements

Vulnerability Details as follows

US Federal agencies must address these vulnerabilities in their systems by January 19, 2023.

Exit mobile version