Jaspersoft CVE-2020-1938 "GhostCat" vulnerability and IGA
book
Article ID: 185905
calendar_today
Updated On:
Products
CA Identity ManagerCA Identity GovernanceCA Identity PortalCA Identity Suite
Issue/Introduction
Is CABI Jaspersoft vulnerable by CVE-2020-1938 "GhostCat" vulnerability?
Environment
Release : 14.2 Jasper 6.1, 7.1.1 and above
Component : IGA suite
Resolution
Out of the box, CABI Jaspersoft is vulnerable by this GhostCat vulnerability. However, this is only due to TIBCO leaving the connector on - though it is not used.
The AJP Connector can be commented out / removed from the server.xml file for CABI Jaspersoft without affecting the product and its integration with Identity Suite.