CVE-2019-17334Incorrect Default Permissions in Software INC Tibco Spotfire Analyst

Severity
8.0HIGHNVD
EPSS
0.4%
top 41.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 24

Description

The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system. This attack is a risk only when the atta

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages10 packages

🔴Vulnerability Details

2
GHSA
GHSA-p7qv-f46f-46p7: The Visualizations component of TIBCO Software Inc2022-05-24
CVEList
TIBCO Spotfire Analyst and Desktop Remote Code Execution Via Shared Files2019-12-17
CVE-2019-17334 — Incorrect Default Permissions | cvebase