PT-2015-7049 · Tibco · Spotfire Analytics Platform+1

Published

2015-10-28

·

Updated

2016-12-07

·

CVE-2015-5713

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TIBCO Spotfire Server versions 5.5.x through 5.5.3 TIBCO Spotfire Server versions 6.0.x through 6.0.4 TIBCO Spotfire Server versions 6.5.x through 6.5.3 TIBCO Spotfire Server versions 7.0.x through 7.0.0 Spotfire Analytics Platform versions prior to 7.0.2
Description The issue allows remote attackers to obtain sensitive log information by visiting an unspecified URL.
Recommendations For TIBCO Spotfire Server versions 5.5.x through 5.5.3, update to version 5.5.4 or later. For TIBCO Spotfire Server versions 6.0.x through 6.0.4, update to version 6.0.5 or later. For TIBCO Spotfire Server versions 6.5.x through 6.5.3, update to version 6.5.4 or later. For TIBCO Spotfire Server versions 7.0.x through 7.0.0, update to version 7.0.1 or later. For Spotfire Analytics Platform versions prior to 7.0.2, update to version 7.0.2 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5713

Affected Products

Spotfire Analytics Platform
Tibco Spotfire Server