PT-2019-15095 · Tibco Software · Tibco Spotfire Server+1
Publicado
2019-12-17
·
Atualizado
2021-07-21
·
CVE-2019-17335
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0
TIBCO Spotfire Server versions 7.11.7 and below
TIBCO Spotfire Server versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.4.0, 10.5.0, and 10.6.0
Description
The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities. These vulnerabilities theoretically allow an attacker access to data cached from a data source, or a portion of a data source, that the attacker should not have access to. The attacker would need privileges to save a Spotfire file to the library.
Recommendations
For TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0, update to a version that contains a fix for this issue.
For TIBCO Spotfire Server versions 7.11.7 and below, update to a version that contains a fix for this issue.
For TIBCO Spotfire Server versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.4.0, 10.5.0, and 10.6.0, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the Data access layer component until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tibco Spotfire Analytics Platform For Aws Marketplace
Tibco Spotfire Server