CVE-2019-17335Sensitive Information Exposure in Software INC Tibco Spotfire Server

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 49.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 24

Description

The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to data cached from a data source, or a portion of a data source, that the attacker should not have access to. The attacker would need privileges to save a Spotfire file to the library. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace:

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-mjxw-wvmv-64gf: The Data access layer component of TIBCO Software Inc2022-05-24
CVEList
TIBCO Spotfire Server Exposes User-Specific Cached Data To Others Users2019-12-17
CVE-2019-17335 — Sensitive Information Exposure | cvebase