alert http $EXTERNAL_NET any -> $HOME_NET any (
msg:"ET EXPLOIT TIBCO JasperReports Directory Traversal Attempt (CVE-2018-18809)";
flow:established,to_server;
http.method;
content:"GET";
http.uri;
content:"/reportresource/reportresource/?";
pcre:"/^resource=net\/sf\/jasperreports\/\.\..+/RUi";
reference:cve,2018-18809;
reference:url,security.elarlang.eu/cve-2018-18809-path-traversal-in-tibco-jaspersoft.html;
classtype:web-application-attack;
sid:2043228; rev:2;
metadata:affected_product Web_Server_Applications, created_at 2023_01_05, cve CVE_2018_18809, deployment Perimeter, deployment Internal, deployment Datacenter, deployment SSLDecrypt, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1083, mitre_technique_name File_And_Directory_Discovery;
target:dest_ip;
)