CVE-2017-3180
Published: Jul 24, 2018
Modified: Aug 5, 2024
Description
Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks. The products and versions that are affected include the following: TIBCO Silver Fabric Enabler for Spotfire Web Player 2.1.2 and earlier TIBCO Spotfire Analyst 7.5.0 TIBCO Spotfire Analyst 7.6.0 TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Analytics Platform for AWS Marketplace 7.0.2 and earlier TIBCO Spotfire Automation Services 6.5.3 and earlier TIBCO Spotfire Automation Services 7.0.0, and 7.0.1 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 6.5.3 and earlier TIBCO Spotfire Deployment Kit 7.0.0, and 7.0.1 TIBCO Spotfire Deployment Kit 7.5.0 TIBCO Spotfire Deployment Kit 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spotfire Desktop 6.5.2 and earlier TIBCO Spotfire Desktop 7.0.0, and 7.0.1 TIBCO Spotfire Desktop 7.5.0 TIBCO Spotfire Desktop 7.6.0 TIBCO Spotfire Desktop 7.7.0 TIBCO Spotfire Desktop Developer Edition 7.7.0 TIBCO Spotfire Desktop Language Packs 7.0.1 and earlier TIBCO Spotfire Desktop Language Packs 7.5.0 TIBCO Spotfire Desktop Language Packs 7.6.0 TIBCO Spotfire Desktop Language Packs 7.7.0 TIBCO Spotfire Professional 6.5.3 and earlier TIBCO Spotfire Professional 7.0.0 and 7.0.1 TIBCO Spotfire Web Player 6.5.3 and earlier TIBCO Spotfire Web Player 7.0.0 and 7.0.1
| Vendor | Product | Versions |
|---|---|---|
TIBCO | Silver Fabric Enabler for Spotfire Web Player | affected 2.1.2 - <= 2.1.2 |
TIBCO | Spotfire Analyst | affected 7.5.0affected 7.6.0affected 7.7.0 |
TIBCO | Spotfire Analytics Platform for AWS Marketplace | affected 7.0.2 - <= 7.0.2 |
TIBCO | Spotfire Automation Services 6 | affected 7.0.0affected 7.0.1affected 6.5.3 - <= 6.5.3 |
TIBCO | Spotfire Connectors | affected 7.6.0 |
TIBCO | Spotfire Deployment Kit | affected 7.0.0affected 7.0.1affected 7.5.0affected 7.6.0affected 7.7.0+1 more versions |
TIBCO | Spotfire Desktop | affected 7.0.0affected 7.0.1affected 7.5.0affected 7.6.0affected 7.7.0+1 more versions |
TIBCO | Spotfire Desktop Developer Edition | affected 7.7.0 |
TIBCO | Spotfire Desktop Language Packs | affected 7.5.0affected 7.6.0affected 7.7.0affected 7.0.1 - <= 7.0.1 |
TIBCO | Spotfire Professional | affected 7.0.0affected 7.0.1affected 6.5.3 - <= 6.5.3 |
TIBCO | Spotfire Web Player | affected 7.0.0affected 7.0.1affected 6.5.3 - <= 6.5.3 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now