CVE-2019-17334
Published: Dec 17, 2019
Modified: Sep 16, 2024
CVSS v3.0
7.6
Description
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system. This attack is a risk only when the attacker has write access to a network file system shared with the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 7.11.1 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, and 10.3.2, versions 10.4.0, 10.5.0, and 10.6.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0, TIBCO Spotfire Deployment Kit: versions 7.11.1 and below, TIBCO Spotfire Desktop: versions 7.11.1 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, and 10.3.2, versions 10.4.0, 10.5.0, and 10.6.0, and TIBCO Spotfire Desktop Language Packs: versions 7.11.1 and below.
| Vendor | Product | Versions |
|---|---|---|
TIBCO Software Inc. | TIBCO Spotfire Analyst | affected unspecified - <= 7.11.1affected 7.12.0affected 7.13.0affected 7.14.0affected 10.0.0+8 more versions |
TIBCO Software Inc. | TIBCO Spotfire Analytics Platform for AWS Marketplace | affected 10.6.0 |
TIBCO Software Inc. | TIBCO Spotfire Deployment Kit | affected unspecified - <= 7.11.1 |
TIBCO Software Inc. | TIBCO Spotfire Desktop | affected unspecified - <= 7.11.1affected 7.12.0affected 7.13.0affected 7.14.0affected 10.0.0+8 more versions |
TIBCO Software Inc. | TIBCO Spotfire Desktop Language Packs | affected unspecified - <= 7.11.1 |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now