TIBCO Software Inc.의 TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS의 Spring 웹 흐름에는 인증된 사용자가 키 구성 파일을 포함하여 웹 애플리케이션의 콘텐츠에 대한 읽기 전용 액세스를 허용할 수 있는 취약점이 포함되어 있습니다. 영향을 받는 릴리스에는 TIBCO Software Inc.의 TIBCO JasperReports Server가 포함됩니다.
TIBCO Software Inc.의 TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS의 Spring 웹 흐름에는 인증된 사용자가 키 구성 파일을 포함하여 웹 애플리케이션의 콘텐츠에 대한 읽기 전용 액세스를 허용할 수 있는 취약점이 포함되어 있습니다. 영향을 받는 릴리스에는 TIBCO Software Inc.의 TIBCO JasperReports Server(6.2.4 이하 버전)가 포함됩니다. 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: 최대 6.4.2 버전, TIBCO JasperReports Server for ActiveMatrix BPM: 최대 버전 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: 최대 버전 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: 최대 6.4.2 버전.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 88.00 |
| 악용 신호(KEV 등재) | ×1.50 |
| VPI | 100.00 |
VPI 공식 vpi-v1 기준
필수 조치
Apply updates per vendor instructions.
| 소스 | CVSS 버전 | 기본 점수 | 심각도 | 벡터 문자열 | 평가일 |
|---|---|---|---|---|---|
| NVDNIST | 3.1 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2026. 04. 20. |
| NVDNIST | 3.0 | 7.7 |
| CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 2026. 04. 20. |
| NVDNIST | 2.0 | 4.0 | MEDIUM | AV:N/AC:L/Au:S/C:P/I:N/A:N | 2026. 04. 20. |