Tibco Spotfire Professional vulnerabilities
4 known vulnerabilities affecting tibco/spotfire_professional.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2017-3180MEDIUMCVSS 5.4≤ 6.5.3v7.0.0+2 more2018-07-24
CVE-2017-3180 [MEDIUM] CWE-20 CVE-2017-3180: Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities becau
Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based aut
cvelistv5nvd
CVE-2015-4554HIGHCVSS 7.5≤ 5.5.1v6.0.0+6 more2015-07-21
CVE-2015-4554 [HIGH] CVE-2015-4554: Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spot
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; S
nvd
CVE-2014-2544HIGHCVSS 7.5≤ 4.0.3v4.5.0+5 more2014-04-10
CVE-2014-2544 [HIGH] CVE-2014-2544: Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authe
Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.
nvd
CVE-2012-0690MEDIUMCVSS 5.0≤ 4.0.12012-03-13
CVE-2012-0690 [MEDIUM] CWE-200 CVE-2012-0690: TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analyti
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a crafted URL.
nvd