PT-2018-7240 · Tibco · Tibco Spotfire Desktop Language Packs+7

Published

2018-07-24

·

Updated

2019-10-09

·

CVE-2017-3181

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TIBCO Spotfire Analyst version 7.7.0 TIBCO Spotfire Connectors version 7.6.0 TIBCO Spotfire Deployment Kit version 7.7.0 TIBCO Spotfire Desktop versions 7.6.0 through 7.7.0 TIBCO Spotfire Desktop Developer Edition version 7.7.0 TIBCO Spotfire Desktop Language Packs versions 7.6.0 through 7.7.0
Description: The issue arises from the failure to properly sanitize user-supplied input before using it in an SQL query, leading to SQL-injection vulnerabilities. This could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Recommendations: For TIBCO Spotfire Analyst version 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Connectors version 7.6.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Deployment Kit version 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Desktop versions 7.6.0 through 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Desktop Developer Edition version 7.7.0, update to a version that properly sanitizes user input. For TIBCO Spotfire Desktop Language Packs versions 7.6.0 through 7.7.0, update to a version that properly sanitizes user input. As a temporary workaround, consider restricting access to the TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3181

Affected Products

Tibco Spotfire Analyst
Tibco Spotfire Client
Tibco Spotfire Connectors
Tibco Spotfire Deployment Kit
Tibco Spotfire Desktop
Tibco Spotfire Desktop Developer Edition
Tibco Spotfire Desktop Language Packs
Tibco Spotfire Web Player Client