PT-2019-15094 · Tibco Software · Tibco Spotfire Deployment Kit+4
Published
2019-12-17
·
Updated
2019-12-27
·
CVE-2019-17334
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO Spotfire Analyst versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0
TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0
TIBCO Spotfire Deployment Kit versions 7.11.1 and below
TIBCO Spotfire Desktop versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0
TIBCO Spotfire Desktop Language Packs versions 7.11.1 and below
Description
The Visualizations component of TIBCO Software Inc.'s products contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system. This attack is a risk only when the attacker has write access to a network file system shared with the affected system.
Recommendations
For TIBCO Spotfire Analyst versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0, update to a version above 10.6.0 or apply the recommended patch.
For TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0, update to a version above 10.6.0 or apply the recommended patch.
For TIBCO Spotfire Deployment Kit versions 7.11.1 and below, update to a version above 7.11.1 or apply the recommended patch.
For TIBCO Spotfire Desktop versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0, update to a version above 10.6.0 or apply the recommended patch.
For TIBCO Spotfire Desktop Language Packs versions 7.11.1 and below, update to a version above 7.11.1 or apply the recommended patch.
As a temporary workaround, consider restricting write access to the Spotfire library and the network file system shared with the affected system.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tibco Spotfire Analyst
Tibco Spotfire Analytics Platform For Aws Marketplace
Tibco Spotfire Deployment Kit
Tibco Spotfire Desktop
Tibco Spotfire Desktop Language Packs