The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2905 The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO Spotfire Statistics Services versions 7.11.1 and below update to version 7.11.2 or higher TIBCO Spotfire Statistics Services version 10.0.0 update to 10.0.1 or higher


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-16T17:53:03.664Z

Reserved: 2019-04-12T00:00:00

Link: CVE-2019-11204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-14T20:29:02.887

Modified: 2024-11-21T04:20:43.287

Link: CVE-2019-11204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.