VendorsTIBCOspotfire_analytics_platform_for_awsall versions
Vulnerabilities

TIBCO Spotfire Analytics Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2019-11210
TIBCO Enterprise Runtime for R Server Exposes Remote Code Execution
Published 2019-09-18 · Modified
10.0EPSS 0.037
CVE-2018-5435
TIBCO Spotfire Product Family Remote Code Execution Vulnerability
Published 2018-06-27 · Modified
10.0EPSS 0.032
CVE-2019-11211
TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Execution
Published 2019-09-18 · Modified
9.9EPSS 0.037
CVE-2020-9408
TIBCO Spotfire Server Script Trust Problem Exposes Remote Code Execution Vulnerability
Published 2020-03-11 · Modified
9.9EPSS 0.013
CVE-2018-18814
TIBCO Spotfire Authentication Vulnerability
Published 2019-01-16 · Modified
9.8EPSS 0.031
CVE-2018-18813
TIBCO Spotfire Reflected and Persistent Cross-Site Scripting Vulnerabilities
Published 2019-01-16 · Modified
8.8EPSS 0.015
CVE-2019-11205
TIBCO Spotfire Server Exposes Multiple Reflected Cross-Site Scripting Vulnerabilities
Published 2019-05-14 · Modified
8.8EPSS 0.013
CVE-2018-5436
TIBCO Spotfire Server information disclosure vulnerabilities
Published 2018-06-27 · Modified
8.8EPSS 0.010
CVE-2018-5437
TIBCO Spotfire Product Family Information Disclosure Vulnerability
Published 2018-06-27 · Modified
8.8EPSS 0.009
CVE-2019-17337
TIBCO Spotfire Server Library Vulnerable to Reflected Cross-Site Scripting
Published 2019-12-17 · Modified
8.1EPSS 0.007
CVE-2019-17334
TIBCO Spotfire Analyst and Desktop Remote Code Execution Via Shared Files
Published 2019-12-17 · Modified
8.0EPSS 0.010
CVE-2019-17336
TIBCO Spotfire Web Player Potentially Exposes Credentials For Shared Data Sources
Published 2019-12-17 · Modified
7.7EPSS 0.009
CVE-2015-4554
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Deployment Kit before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Desktop before 6.5.2 and 7.0.x before 7.0.1; Spotfire Desktop Language Packs 7.0.x before 7.0.1; Spotfire Professional before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Web Player before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; and Silver Fabric Enabler for Spotfire Web Player before 2.1.1 allow remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.
Published 2015-07-21 · Modified
7.5EPSS 0.035
CVE-2018-18812
TIBCO Spotfire Fails To Prevent Write Access to Spotfire Library
Published 2019-01-16 · Modified
6.5EPSS 0.012
CVE-2017-5527
TIBCO Spotfire injection vulnerabilities
Published 2017-05-09 · Modified
6.5EPSS 0.009
CVE-2019-17335
TIBCO Spotfire Server Exposes User-Specific Cached Data To Others Users
Published 2019-12-17 · Modified
6.5EPSS 0.008
CVE-2017-3180
Multiple TIBCO Spotfire components fail to sanitize user-supplied inout and are vulnerable to cross-site scripting
Published 2018-07-24 · Modified
5.4EPSS 0.006
CVE-2019-11206
TIBCO Spotfire Server Vulnerabilities With Integrity of Comments and Bookmarks
Published 2019-05-14 · Modified
5.3EPSS 0.016
CVE-2015-5713
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote attackers to obtain sensitive log information by visiting an unspecified URL.
Published 2015-10-28 · Modified
5.0EPSS 0.021
CVE-2015-5712
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.
Published 2015-10-28 · Modified
4.0EPSS 0.017