CVE-2019-11206Software INC Tibco Spotfire Analytics Platform FOR AWS Marketplace vulnerability

3 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 50.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 24

Description

The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow a malicious user to undermine the integrity of comments and bookmarks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.2.0, and TIBCO Spotfire Server: versions up to and including 7.11.2; 7.12.0; 7.13.0; 7.14.0; 10.0.0; 10.0.1; 10

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-mj38-74cg-x364: The Spotfire library component of TIBCO Software Inc2022-05-24
CVEList
TIBCO Spotfire Server Vulnerabilities With Integrity of Comments and Bookmarks2019-05-14
CVE-2019-11206 — MEDIUM severity | cvebase