VendorsTIBCOspotfire_serverall versions
Vulnerabilities

TIBCO Spotfire Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2020-9408
TIBCO Spotfire Server Script Trust Problem Exposes Remote Code Execution Vulnerability
Published 2020-03-11 · Modified
9.9EPSS 0.013
CVE-2018-18814
TIBCO Spotfire Authentication Vulnerability
Published 2019-01-16 · Modified
9.8EPSS 0.031
CVE-2022-41558
TIBCO Spotfire Stored Cross Site Scripting (XSS) Vulnerability
Published 2022-11-15 · Modified
9.0EPSS 0.005
CVE-2018-18813
TIBCO Spotfire Reflected and Persistent Cross-Site Scripting Vulnerabilities
Published 2019-01-16 · Modified
8.8EPSS 0.015
CVE-2019-11205
TIBCO Spotfire Server Exposes Multiple Reflected Cross-Site Scripting Vulnerabilities
Published 2019-05-14 · Modified
8.8EPSS 0.013
CVE-2018-5436
TIBCO Spotfire Server information disclosure vulnerabilities
Published 2018-06-27 · Modified
8.8EPSS 0.010
CVE-2021-28830
TIBCO Spotfire Windows Platform Artifact Search vulnerability
Published 2021-06-29 · Modified
8.8EPSS 0.003
CVE-2021-23275
TIBCO Spotfire Windows Platform Installation vulnerability
Published 2021-06-29 · Modified
8.8EPSS 0.002
CVE-2021-43051
TIBCO Spotfire Server API Authorization Vulnerability
Published 2021-12-14 · Modified
8.5EPSS 0.008
CVE-2022-30579
TIBCO Spotfire Server Blind SSRF vulnerability
Published 2022-09-20 · Modified
8.4EPSS 0.006
CVE-2020-9416
TIBCO Spotfire Stored Cross Site Scripting Vulnerability
Published 2020-09-15 · Modified
8.2EPSS 0.006
CVE-2019-17337
TIBCO Spotfire Server Library Vulnerable to Reflected Cross-Site Scripting
Published 2019-12-17 · Modified
8.1EPSS 0.007
CVE-2021-23273
TIBCO Spotfire Cross Site Scripting Vulnerability
Published 2021-03-09 · Modified
8.0EPSS 0.006
CVE-2019-17336
TIBCO Spotfire Web Player Potentially Exposes Credentials For Shared Data Sources
Published 2019-12-17 · Modified
7.7EPSS 0.009
CVE-2014-2544
Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Automation Services 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Deployment Kit 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Desktop 6.x before 6.0.1; and Spotfire Analyst 6.x before 6.0.1 allows remote attackers to execute arbitrary code via unknown vectors.
Published 2014-04-09 · Modified
7.5EPSS 0.031
CVE-2011-3134
Unspecified vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.
Published 2011-09-02 · Modified
7.5EPSS 0.022
CVE-2014-5285
Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x before 5.5.2, 6.0.x before 6.0.3, and 6.5.x before 6.5.1 allows remote attackers to gain privileges, and obtain sensitive information or modify data, via unknown vectors.
Published 2014-09-04 · Modified
7.5EPSS 0.020
CVE-2018-18812
TIBCO Spotfire Fails To Prevent Write Access to Spotfire Library
Published 2019-01-16 · Modified
6.5EPSS 0.012
CVE-2017-5527
TIBCO Spotfire injection vulnerabilities
Published 2017-05-09 · Modified
6.5EPSS 0.009
CVE-2019-17335
TIBCO Spotfire Server Exposes User-Specific Cached Data To Others Users
Published 2019-12-17 · Modified
6.5EPSS 0.008
CVE-2023-26220
TIBCO Spotfire Stored Cross-site Scripting (XSS) vulnerability
Published 2023-10-10 · Modified
5.4EPSS 0.003
CVE-2019-11206
TIBCO Spotfire Server Vulnerabilities With Integrity of Comments and Bookmarks
Published 2019-05-14 · Modified
5.3EPSS 0.016
CVE-2015-5713
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote attackers to obtain sensitive log information by visiting an unspecified URL.
Published 2015-10-28 · Modified
5.0EPSS 0.021
CVE-2012-0690
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a crafted URL.
Published 2012-03-13 · Modified
5.0EPSS 0.016
CVE-2023-26221
TIBCO Spotfire Insufficiently Protected Credential vulnerability
Published 2023-11-08 · Modified
5.0EPSS 0.002
CVE-2011-3133
Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to hijack web sessions via unspecified vectors.
Published 2011-09-02 · Modified
4.3EPSS 0.017
CVE-2011-3132
Cross-site scripting (XSS) vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-09-02 · Modified
4.3EPSS 0.017
CVE-2015-5712
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.
Published 2015-10-28 · Modified
4.0EPSS 0.017