PT-2018-11151 · Tibco Software · Tibco Spotfire Statistics Services
Published
2018-10-10
·
Updated
2019-10-09
·
CVE-2018-12410
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO Spotfire Statistics Services versions up to and including 7.11.0
Description
The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple issues that may allow remote code execution. An attacker may be able to execute code with the permissions of the system account used to run the web server component without needing to authenticate.
Recommendations
For TIBCO Spotfire Statistics Services versions up to and including 7.11.0, update to a version later than 7.11.0 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tibco Spotfire Statistics Services