Description
The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0.
Published: 2018-06-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Spotfire Analytics Platform for AWS Marketplace versions 7.12.0 and below update to version 7.13.0 or higher TIBCO Spotfire Server versions 7.8.1 and below update to version 7.8.2 or higher TIBCO Spotfire Server version 7.9.0 update to version 7.9.1 or higher TIBCO Spotfire Server version 7.10.0 update to version 7.10.1 or higher TIBCO Spotfire Server version 7.11.0 update to version 7.11.1 or higher TIBCO Spotfire Server version 7.12.0 update to version 7.13.0 or higher

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-17206 The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0.
History

No history.

Subscriptions

Tibco Spotfire Analytics Platform For Aws Spotfire Server
cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-17T01:26:22.747Z

Reserved: 2018-01-12T00:00:00.000Z

Link: CVE-2018-5436

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-27T16:29:00.397

Modified: 2024-11-21T04:08:47.970

Link: CVE-2018-5436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses