PT-2023-20548 · Tibco · Tibco Spotfire Server+1
Publicado
2023-10-10
·
Atualizado
2023-10-18
·
CVE-2023-26220
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TIBCO Spotfire Analyst versions 11.4.7 and below, 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.1.1
TIBCO Spotfire Server versions 11.4.11 and below, 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.0.5, 12.1.0, 12.1.1
Description
The Spotfire Library component contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker.
Recommendations
For TIBCO Spotfire Analyst versions 11.4.7 and below, 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.1.1, update to a version that is not affected by this vulnerability.
For TIBCO Spotfire Server versions 11.4.11 and below, 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.0.5, 12.1.0, 12.1.1, update to a version that is not affected by this vulnerability.
As a temporary workaround, consider disabling the Spotfire Library component until a patch is available.
Restrict access to the affected system to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tibco Spotfire Analyst
Tibco Spotfire Server