CVE-2017-3181SQL Injection in Spotfire Analyst

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateMay 13

Description

Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The following products and versions are affected: TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spot

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages11 packages

CVEListV5tibco/spotfire_desktop_language_packs7.6.0, 7.7.0+1
CVEListV5tibco/spotfire_desktop7.6.0, 7.7.0+1
NVDtibco/spotfire_desktop7.6.0, 7.7.0+1

🔴Vulnerability Details

2
GHSA
GHSA-gxcx-xp38-vxx9: Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input befo2022-05-13
CVEList
Multiple TIBCO Spotfire components are vulnerable to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query2018-07-24
CVE-2017-3181 — SQL Injection in Tibco Spotfire Analyst | cvebase