CVE Database
/

CVE-2018-5435

Back to search

CVE-2018-5435

Published: Jun 27, 2018

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

9.6

CRITICAL

Description

The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

VendorProductVersions

TIBCO Software Inc.

TIBCO Spotfire Analyst

affected
unspecified - <= 7.8.0
affected
7.9.0
affected
7.9.1
affected
7.10.0
affected
7.10.1

+2 more versions

TIBCO Software Inc.

TIBCO Spotfire Analytics Platform for AWS Marketplace

affected
unspecified - <= 7.12.0

TIBCO Software Inc.

TIBCO Spotfire Deployment Kit

affected
unspecified - <= 7.8.0
affected
7.9.0
affected
7.9.1
affected
7.10.0
affected
7.10.1

+2 more versions

TIBCO Software Inc.

TIBCO Spotfire Desktop

affected
unspecified - <= 7.8.0
affected
7.9.0
affected
7.9.1
affected
7.10.0
affected
7.10.1

+2 more versions

TIBCO Software Inc.

TIBCO Spotfire Desktop Language Packs

affected
unspecified - <= 7.8.0
affected
7.9.0
affected
7.9.1
affected
7.10.0
affected
7.10.1

+1 more versions

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now