Answer in brief
CVE-2018-5430 records a High severity vulnerability in TIBCO JasperReports Server Information Disclosure Vulnerability. The current sources mark it as known exploited. The current feed maps TIBCO Software Inc./TIBCO JasperReports Server (generic), TIBCO Software Inc./TIBCO JasperReports Server Community Edition (generic), TIBCO Software Inc./TIBCO JasperReports Server for ActiveMatrix BPM (generic), TIBCO Software Inc./TIBCO Jaspersoft for AWS with Multi-Tenancy (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TIBCO Software Inc./TIBCO JasperReports Server (generic), TIBCO Software Inc./TIBCO JasperReports Server Community Edition (generic), TIBCO Software Inc./TIBCO JasperReports Server for ActiveMatrix BPM (generic), TIBCO Software Inc./TIBCO Jaspersoft for AWS with Multi-Tenancy (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TIBCO Software Inc./TIBCO JasperReports Servergeneric | unspecified || 6.3.0 || 6.3.2 || 6.3.3 || 6.4.0 || 6.4.2 | Not reported |
| TIBCO Software Inc./TIBCO JasperReports Server Community Editiongeneric | unspecified | Not reported |
| TIBCO Software Inc./TIBCO JasperReports Server for ActiveMatrix BPMgeneric | unspecified | Not reported |
| TIBCO Software Inc./TIBCO Jaspersoft for AWS with Multi-Tenancygeneric | unspecified | Not reported |
| TIBCO Software Inc./TIBCO Jaspersoft Reporting and Analytics for AWSgeneric | unspecified | Not reported |
Published upstream
Apr 17, 2018
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 29, 2022
Evidence: source:kev:kev:kev:recordThe Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
Quoted source text, attributed separately from HOL analysis.