PT-2015-7048 · Tibco · Spotfire Analytics Platform+1

Publicado

2015-10-28

·

Atualizado

2016-12-07

·

CVE-2015-5712

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TIBCO Spotfire Server versions 5.5.x through 5.5.3 TIBCO Spotfire Server versions 6.0.x through 6.0.4 TIBCO Spotfire Server versions 6.5.x through 6.5.3 TIBCO Spotfire Server versions 7.0.x through 7.0.0 Spotfire Analytics Platform versions prior to 7.0.2
Description The issue allows remote authenticated users to obtain sensitive system information by visiting an unspecified URL.
Recommendations For TIBCO Spotfire Server versions 5.5.x through 5.5.3, update to version 5.5.4 or later. For TIBCO Spotfire Server versions 6.0.x through 6.0.4, update to version 6.0.5 or later. For TIBCO Spotfire Server versions 6.5.x through 6.5.3, update to version 6.5.4 or later. For TIBCO Spotfire Server versions 7.0.x through 7.0.0, update to version 7.0.1 or later. For Spotfire Analytics Platform versions prior to 7.0.2, update to version 7.0.2 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-5712

Produtos afetados

Spotfire Analytics Platform
Tibco Spotfire Server