PT-2018-7240 · Tibco · Tibco Spotfire Desktop Language Packs+7

Publicado

2018-07-24

·

Atualizado

2019-10-09

·

CVE-2017-3181

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TIBCO Spotfire Analyst version 7.7.0 TIBCO Spotfire Connectors version 7.6.0 TIBCO Spotfire Deployment Kit version 7.7.0 TIBCO Spotfire Desktop versions 7.6.0 through 7.7.0 TIBCO Spotfire Desktop Developer Edition version 7.7.0 TIBCO Spotfire Desktop Language Packs versions 7.6.0 through 7.7.0
Description: The issue arises from the failure to properly sanitize user-supplied input before using it in an SQL query, leading to SQL-injection vulnerabilities. This could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Recommendations: For TIBCO Spotfire Analyst version 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Connectors version 7.6.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Deployment Kit version 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Desktop versions 7.6.0 through 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Desktop Developer Edition version 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Desktop Language Packs versions 7.6.0 through 7.7.0, update to a version that properly sanitizes user input. As a temporary workaround, consider restricting access to the TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components until a patch is available.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3181

Produtos afetados

Tibco Spotfire Analyst
Tibco Spotfire Client
Tibco Spotfire Connectors
Tibco Spotfire Deployment Kit
Tibco Spotfire Desktop
Tibco Spotfire Desktop Developer Edition
Tibco Spotfire Desktop Language Packs
Tibco Spotfire Web Player Client