CVE Database
/

CVE-2021-28830

Back to search

CVE-2021-28830

Published: Jun 29, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Statistics Services, TIBCO Spotfire Statistics Services, and TIBCO Spotfire Statistics Services contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from the affected component searching for run-time artifacts outside of the installation hierarchy. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition: versions 1.2.4 and below, TIBCO Enterprise Runtime for R - Server Edition: versions 1.3.0 and 1.3.1, TIBCO Enterprise Runtime for R - Server Edition: versions 1.4.0, 1.5.0, and 1.6.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 11.3.0 and below, TIBCO Spotfire Server: versions 10.3.12 and below, TIBCO Spotfire Server: versions 10.4.0, 10.5.0, 10.6.0, 10.6.1, 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, 10.10.1, 10.10.2, 10.10.3, and 10.10.4, TIBCO Spotfire Server: versions 11.0.0, 11.1.0, 11.2.0, and 11.3.0, TIBCO Spotfire Statistics Services: versions 10.3.0 and below, TIBCO Spotfire Statistics Services: versions 10.10.0, 10.10.1, and 10.10.2, and TIBCO Spotfire Statistics Services: versions 11.1.0, 11.2.0, and 11.3.0.

VendorProductVersions

TIBCO Software Inc.

TIBCO Enterprise Runtime for R - Server Edition

affected
unspecified - <= 1.2.4

TIBCO Software Inc.

TIBCO Enterprise Runtime for R - Server Edition

affected
1.3.0
affected
1.3.1

TIBCO Software Inc.

TIBCO Enterprise Runtime for R - Server Edition

affected
1.4.0
affected
1.5.0
affected
1.6.0

TIBCO Software Inc.

TIBCO Spotfire Analytics Platform for AWS Marketplace

affected
unspecified - <= 11.3.0

TIBCO Software Inc.

TIBCO Spotfire Server

affected
unspecified - <= 10.3.12

TIBCO Software Inc.

TIBCO Spotfire Server

affected
10.4.0
affected
10.5.0
affected
10.6.0
affected
10.6.1
affected
10.7.0

+8 more versions

TIBCO Software Inc.

TIBCO Spotfire Server

affected
11.0.0
affected
11.1.0
affected
11.2.0
affected
11.3.0

TIBCO Software Inc.

TIBCO Spotfire Statistics Services

affected
unspecified - <= 10.3.0

TIBCO Software Inc.

TIBCO Spotfire Statistics Services

affected
10.10.0
affected
10.10.1
affected
10.10.2

TIBCO Software Inc.

TIBCO Spotfire Statistics Services

affected
11.1.0
affected
11.2.0
affected
11.3.0

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now