TIBCO Spotfire Analytics Platform for AWS Marketplace和TIBCO Spotfire Server中的Spotfire library组件存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。以下产品及版本受到影响:TIBCO Spotfire Analytics Platform for AWS Marketplace 10.6.0版本;TIBCO Spotfire Server 7.11.7及之前版本,7
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TIBCO Software Inc. | TIBCO Spotfire Analytics Platform for AWS Marketplace | 10.6.0 | - |
|
| TIBCO Software Inc. | TIBCO Spotfire Server | unspecified ~ 7.11.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-17335 | TIBCO Spotfire Server Exposes User-Specific Cached Data To Others Users | |
| CVE-2019-17336 | TIBCO Spotfire Web Player Potentially Exposes Credentials For Shared Data Sources | |
| CVE-2019-17334 | TIBCO Spotfire Analyst and Desktop Remote Code Execution Via Shared Files |
No comments yet