PT-2018-7240 · Tibco · Tibco Spotfire Desktop Language Packs+7
Publicado
2018-07-24
·
Atualizado
2019-10-09
·
CVE-2017-3181
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
TIBCO Spotfire Analyst version 7.7.0
TIBCO Spotfire Connectors version 7.6.0
TIBCO Spotfire Deployment Kit version 7.7.0
TIBCO Spotfire Desktop versions 7.6.0 through 7.7.0
TIBCO Spotfire Desktop Developer Edition version 7.7.0
TIBCO Spotfire Desktop Language Packs versions 7.6.0 through 7.7.0
Description:
The issue arises from the failure to properly sanitize user-supplied input before using it in an SQL query, leading to SQL-injection vulnerabilities. This could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Recommendations:
For TIBCO Spotfire Analyst version 7.7.0, update to a version that properly sanitizes user input.
For TIBCO Spotfire Connectors version 7.6.0, update to a version that properly sanitizes user input.
For TIBCO Spotfire Deployment Kit version 7.7.0, update to a version that properly sanitizes user input.
For TIBCO Spotfire Desktop versions 7.6.0 through 7.7.0, update to a version that properly sanitizes user input.
For TIBCO Spotfire Desktop Developer Edition version 7.7.0, update to a version that properly sanitizes user input.
For TIBCO Spotfire Desktop Language Packs versions 7.6.0 through 7.7.0, update to a version that properly sanitizes user input.
As a temporary workaround, consider restricting access to the TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components until a patch is available.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tibco Spotfire Analyst
Tibco Spotfire Client
Tibco Spotfire Connectors
Tibco Spotfire Deployment Kit
Tibco Spotfire Desktop
Tibco Spotfire Desktop Developer Edition
Tibco Spotfire Desktop Language Packs
Tibco Spotfire Web Player Client