CVE Database
/

CVE-2019-17334

Back to search

CVE-2019-17334

Published: Dec 17, 2019

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

7.6

HIGH

Description

The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system. This attack is a risk only when the attacker has write access to a network file system shared with the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 7.11.1 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, and 10.3.2, versions 10.4.0, 10.5.0, and 10.6.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0, TIBCO Spotfire Deployment Kit: versions 7.11.1 and below, TIBCO Spotfire Desktop: versions 7.11.1 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, and 10.3.2, versions 10.4.0, 10.5.0, and 10.6.0, and TIBCO Spotfire Desktop Language Packs: versions 7.11.1 and below.

VendorProductVersions

TIBCO Software Inc.

TIBCO Spotfire Analyst

affected
unspecified - <= 7.11.1
affected
7.12.0
affected
7.13.0
affected
7.14.0
affected
10.0.0

+8 more versions

TIBCO Software Inc.

TIBCO Spotfire Analytics Platform for AWS Marketplace

affected
10.6.0

TIBCO Software Inc.

TIBCO Spotfire Deployment Kit

affected
unspecified - <= 7.11.1

TIBCO Software Inc.

TIBCO Spotfire Desktop

affected
unspecified - <= 7.11.1
affected
7.12.0
affected
7.13.0
affected
7.14.0
affected
10.0.0

+8 more versions

TIBCO Software Inc.

TIBCO Spotfire Desktop Language Packs

affected
unspecified - <= 7.11.1

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2019-17334 | HIGH (7.6) - Security Vulnerability | QwikSec