VendorsTIBCOspotfire_deployment_kitall versions
Vulnerabilities

TIBCO Spotfire Deployment Kit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2018-5435
TIBCO Spotfire Product Family Remote Code Execution Vulnerability
Published 2018-06-27 · Modified
10.0EPSS 0.032
CVE-2017-3181
Multiple TIBCO Spotfire components are vulnerable to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query
Published 2018-07-24 · Modified
9.8EPSS 0.017
CVE-2025-3115
Spotfire Data Function Vulnerability
Published 2025-04-09 · Modified
9.8EPSS 0.007
CVE-2018-5437
TIBCO Spotfire Product Family Information Disclosure Vulnerability
Published 2018-06-27 · Modified
8.8EPSS 0.009
CVE-2019-17334
TIBCO Spotfire Analyst and Desktop Remote Code Execution Via Shared Files
Published 2019-12-17 · Modified
8.0EPSS 0.010
CVE-2015-4554
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Deployment Kit before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Desktop before 6.5.2 and 7.0.x before 7.0.1; Spotfire Desktop Language Packs 7.0.x before 7.0.1; Spotfire Professional before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Web Player before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; and Silver Fabric Enabler for Spotfire Web Player before 2.1.1 allow remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.
Published 2015-07-21 · Modified
7.5EPSS 0.035
CVE-2017-3180
Multiple TIBCO Spotfire components fail to sanitize user-supplied inout and are vulnerable to cross-site scripting
Published 2018-07-24 · Modified
5.4EPSS 0.006
CVE-2014-7195
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.
Published 2014-11-21 · Modified
4.0EPSS 0.009