PT-2019-15096 · Tibco Software · Tibco Spotfire Server+1

Publicado

2019-12-17

·

Atualizado

2020-08-24

·

CVE-2019-17336

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0 TIBCO Spotfire Server versions 7.11.7 and below TIBCO Spotfire Server versions 7.12.0 through 10.6.0
Description The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to information that can lead to obtaining credentials used to access Spotfire data sources. The attacker would need privileges to save a Spotfire file to the library, and only applies in a situation where NTLM credentials, or a credentials profile is in use.
Recommendations For TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0, update to a version that contains a fix for this issue. For TIBCO Spotfire Server versions 7.11.7 and below, update to a version that contains a fix for this issue. For TIBCO Spotfire Server versions 7.12.0 through 10.6.0, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the Data access layer component until a patch is available. Restrict the use of NTLM credentials or credentials profiles to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-17336

Produtos afetados

Tibco Spotfire Analytics Platform For Aws Marketplace
Tibco Spotfire Server