Tibco Spotfire Analytics Server vulnerabilities

4 known vulnerabilities affecting tibco/spotfire_analytics_server.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2012-0690MEDIUMCVSS 5.0v10.0.0v10.0.12012-03-13
CVE-2012-0690 [MEDIUM] CWE-200 CVE-2012-0690: TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analyti TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a crafted URL.
nvd
CVE-2011-3134HIGHCVSS 7.5≤ 10.0.1v10.0.02011-09-02
CVE-2011-3134 [HIGH] CVE-2011-3134: Unspecified vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x bef Unspecified vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.
nvd
CVE-2011-3133MEDIUMCVSS 4.3≤ 10.0.1v10.0.02011-09-02
CVE-2011-3133 [MEDIUM] CVE-2011-3133: Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2. Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2011-3132MEDIUMCVSS 4.3≤ 10.0.1v10.0.02011-09-02
CVE-2011-3132 [MEDIUM] CWE-79 CVE-2011-3132: Cross-site scripting (XSS) vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3 Cross-site scripting (XSS) vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
Tibco Spotfire Analytics Server vulnerabilities | cvebase