PT-2019-15094 · Tibco Software · Tibco Spotfire Deployment Kit+4

Published

2019-12-17

·

Updated

2019-12-27

·

CVE-2019-17334

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIBCO Spotfire Analyst versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0 TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0 TIBCO Spotfire Deployment Kit versions 7.11.1 and below TIBCO Spotfire Desktop versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0 TIBCO Spotfire Desktop Language Packs versions 7.11.1 and below
Description The Visualizations component of TIBCO Software Inc.'s products contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system. This attack is a risk only when the attacker has write access to a network file system shared with the affected system.
Recommendations For TIBCO Spotfire Analyst versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0, update to a version above 10.6.0 or apply the recommended patch. For TIBCO Spotfire Analytics Platform for AWS Marketplace version 10.6.0, update to a version above 10.6.0 or apply the recommended patch. For TIBCO Spotfire Deployment Kit versions 7.11.1 and below, update to a version above 7.11.1 or apply the recommended patch. For TIBCO Spotfire Desktop versions 7.11.1 and below, 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.5.0, and 10.6.0, update to a version above 10.6.0 or apply the recommended patch. For TIBCO Spotfire Desktop Language Packs versions 7.11.1 and below, update to a version above 7.11.1 or apply the recommended patch. As a temporary workaround, consider restricting write access to the Spotfire library and the network file system shared with the affected system.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17334

Affected Products

Tibco Spotfire Analyst
Tibco Spotfire Analytics Platform For Aws Marketplace
Tibco Spotfire Deployment Kit
Tibco Spotfire Desktop
Tibco Spotfire Desktop Language Packs