The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component. Affected releases are TIBCO Software Inc. TIBCO Spotfire Statistics Services versions up to and including 7.11.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-4384 The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component. Affected releases are TIBCO Software Inc. TIBCO Spotfire Statistics Services versions up to and including 7.11.0.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. In addition to the updates, security related configuration changes may be required due to new defaults. Please review the documentation. For each affected system, update to the corresponding software versions: - TIBCO Spotfire Statistics Services versions 7.11.0 and below update to version 7.11.1 or higher


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-16T17:04:15.928Z

Reserved: 2018-06-14T00:00:00

Link: CVE-2018-12410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-10T20:29:00.273

Modified: 2024-11-21T03:45:10.183

Link: CVE-2018-12410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.