Tibco Software Inc Tibco Spotfire Server vulnerabilities
17 known vulnerabilities affecting tibco_software_inc/tibco_spotfire_server.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM11
Vulnerabilities
Page 1 of 1
CVE-2022-41558MEDIUMCVSS 5.4≥ unspecified, ≤ 11.4.8v11.5.0+10 more2022-11-15
CVE-2022-41558 [MEDIUM] CWE-79 CVE-2022-41558: The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains an easily exploita
cvelistv5nvd
CVE-2022-30579HIGHCVSS 8.4v12.0.02022-09-20
CVE-2022-30579 [HIGH] CWE-918 CVE-2022-30579: The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpl
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s
cvelistv5nvd
CVE-2021-43051MEDIUMCVSS 6.8≥ unspecified, ≤ 10.10.6v11.0.0+7 more2021-12-14
CVE-2021-43051 [MEDIUM] CVE-2021-43051: The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server,
The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows malicious custom API clients with network access to execute internal API operations outside of the scope of those granted to it. A successful attack using this vulnerability
cvelistv5nvd
CVE-2021-23275HIGHCVSS 7.8≥ unspecified, ≤ 10.3.12v10.4.0+16 more2021-06-29
CVE-2021-23275 [HIGH] CWE-732 CVE-2021-23275: The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Statisti
cvelistv5nvd
CVE-2021-28830HIGHCVSS 7.8≥ unspecified, ≤ 10.3.12v10.4.0+16 more2021-06-29
CVE-2021-28830 [HIGH] CVE-2021-28830: The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIB
The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire S
cvelistv5nvd
CVE-2021-23273MEDIUMCVSS 5.4≥ unspecified, ≤ 10.3.11v10.10.0+9 more2021-03-09
CVE-2021-23273 [MEDIUM] CWE-79 CVE-2021-23273: The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyt
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected s
cvelistv5nvd
CVE-2020-9416MEDIUMCVSS 5.4v10.7.0v10.8.0+4 more2020-09-15
CVE-2020-9416 [MEDIUM] CWE-79 CVE-2020-9416: The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyt
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a legitimate user to inject scripts. If executed by a victim authenticated to the affected system these scripts will be
cvelistv5nvd
CVE-2020-9408HIGHCVSS 8.8≥ unspecified, ≤ 7.11.9v7.12.0+19 more2020-03-11
CVE-2020-9408 [HIGH] CWE-276 CVE-2020-9408: The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Ma
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permissions to the Spotfire Library, but not "Script Author" group permission, to modify attributes of files and objects saved to the library suc
cvelistv5nvd
CVE-2019-17336MEDIUMCVSS 6.5≥ unspecified, ≤ 7.11.7v7.12.0+15 more2019-12-17
CVE-2019-17336 [MEDIUM] CVE-2019-17336: The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS M
The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to information that can lead to obtaining credentials used to access Spotfire data sources. The attacker would need privileges to save a Spotfir
cvelistv5nvd
CVE-2019-17335MEDIUMCVSS 6.5≥ unspecified, ≤ 7.11.7v7.12.0+15 more2019-12-17
CVE-2019-17335 [MEDIUM] CVE-2019-17335: The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS M
The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to data cached from a data source, or a portion of a data source, that the attacker should not have access to. The attacker would need privilege
cvelistv5nvd
CVE-2019-17337MEDIUMCVSS 5.4≥ unspecified, ≤ 7.11.7v7.12.0+15 more2019-12-17
CVE-2019-17337 [MEDIUM] CWE-79 CVE-2019-17337: The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Ma
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflected cross-site scripting (XSS) attack. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpla
cvelistv5nvd
CVE-2019-11205MEDIUMCVSS 6.1v7.14.0v10.0.0+3 more2019-05-14
CVE-2019-11205 [MEDIUM] CWE-79 CVE-2019-11205: The web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpl
The web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: 7.14.0; 7.14.1; 10.0.0; 10
cvelistv5nvd
CVE-2019-11206MEDIUMCVSS 5.3≥ unspecified, ≤ 7.11.2v7.12.0+6 more2019-05-14
CVE-2019-11206 [MEDIUM] CVE-2019-11206: The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Ma
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow a malicious user to undermine the integrity of comments and bookmarks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: ve
cvelistv5nvd
CVE-2018-18814CRITICALCVSS 9.8≥ unspecified, ≤ 7.10.1v7.11.0+4 more2019-01-16
CVE-2018-18814 [CRITICAL] CWE-287 CVE-2018-18814: The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platfo
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker to gain full access to a target account, independent of configured authentication mechanisms. A
cvelistv5nvd
CVE-2018-18813MEDIUMCVSS 6.1≥ unspecified, ≤ 7.10.1v7.11.0+5 more2019-01-16
CVE-2018-18813 [MEDIUM] CWE-79 CVE-2018-18813: The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS
The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up
cvelistv5nvd
CVE-2018-5436HIGHCVSS 8.8≥ unspecified, ≤ 7.8.1v7.9.0+3 more2018-06-27
CVE-2018-5436 [HIGH] CWE-200 CVE-2018-5436: The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Mar
The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Market
cvelistv5nvd
CVE-2017-5527MEDIUMCVSS 6.5v7.0.0v7.0.1+4 more2017-05-09
CVE-2017-5527 [MEDIUM] CWE-89 CVE-2017-5527: TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1
TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.
cvelistv5nvd