PT-2018-11151 · Tibco Software · Tibco Spotfire Statistics Services

Published

2018-10-10

·

Updated

2019-10-09

·

CVE-2018-12410

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIBCO Spotfire Statistics Services versions up to and including 7.11.0
Description The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple issues that may allow remote code execution. An attacker may be able to execute code with the permissions of the system account used to run the web server component without needing to authenticate.
Recommendations For TIBCO Spotfire Statistics Services versions up to and including 7.11.0, update to a version later than 7.11.0 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-12410

Affected Products

Tibco Spotfire Statistics Services