TIBCO Spotfire Server Exposes Multiple Reflected Cross-Site Scripting Vulnerabilities
CVE-2019-11205
8.8HIGH
Summary
The web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: 7.14.0; 7.14.1; 10.0.0; 10.0.1; 10.1.0; 10.2.0, and TIBCO Spotfire Server: 7.14.0; 10.0.0; 10.0.1; 10.1.0; 10.2.0.
Affected Version(s)
TIBCO Spotfire Analytics Platform for AWS Marketplace 7.14.0
TIBCO Spotfire Analytics Platform for AWS Marketplace 7.14.1
TIBCO Spotfire Analytics Platform for AWS Marketplace 10.0.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database