VendorsTIBCOspotfire_analytics_platform_for_awsany version
Vulnerabilities

TIBCO Spotfire Analytics Platform any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2018-5435
TIBCO Spotfire Product Family Remote Code Execution Vulnerability
Published 2018-06-27 · Modified
10.0EPSS 0.032
CVE-2020-9408
TIBCO Spotfire Server Script Trust Problem Exposes Remote Code Execution Vulnerability
Published 2020-03-11 · Modified
9.9EPSS 0.013
CVE-2018-18814
TIBCO Spotfire Authentication Vulnerability
Published 2019-01-16 · Modified
9.8EPSS 0.031
CVE-2018-18813
TIBCO Spotfire Reflected and Persistent Cross-Site Scripting Vulnerabilities
Published 2019-01-16 · Modified
8.8EPSS 0.015
CVE-2018-5436
TIBCO Spotfire Server information disclosure vulnerabilities
Published 2018-06-27 · Modified
8.8EPSS 0.010
CVE-2018-5437
TIBCO Spotfire Product Family Information Disclosure Vulnerability
Published 2018-06-27 · Modified
8.8EPSS 0.009
CVE-2018-18812
TIBCO Spotfire Fails To Prevent Write Access to Spotfire Library
Published 2019-01-16 · Modified
6.5EPSS 0.012
CVE-2017-5527
TIBCO Spotfire injection vulnerabilities
Published 2017-05-09 · Modified
6.5EPSS 0.009
CVE-2017-3180
Multiple TIBCO Spotfire components fail to sanitize user-supplied inout and are vulnerable to cross-site scripting
Published 2018-07-24 · Modified
5.4EPSS 0.006
CVE-2019-11206
TIBCO Spotfire Server Vulnerabilities With Integrity of Comments and Bookmarks
Published 2019-05-14 · Modified
5.3EPSS 0.016
CVE-2015-5713
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote attackers to obtain sensitive log information by visiting an unspecified URL.
Published 2015-10-28 · Modified
5.0EPSS 0.021
CVE-2015-5712
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.
Published 2015-10-28 · Modified
4.0EPSS 0.017