CVE-2019-11205
TIBCO Spotfire Server Exposes Multiple Reflected Cross-Site Scripting Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: 7.14.0; 7.14.1; 10.0.0; 10.0.1; 10.1.0; 10.2.0, and TIBCO Spotfire Server: 7.14.0; 10.0.0; 10.0.1; 10.1.0; 10.2.0.
El componente Web Server de TIBCO Software Inc. TIBCO Spotfire Analytics Platform para AWS Marketplace, y TIBCO Spotfire Server posee vulnerabilidades que teóricamente permiten ataques reflejados de secuencias de tipo cross-site (XSS). Las versiones afectadas son la plataforma TIBCO Spotfire Analytics de TIBCO Software Inc. para AWS Marketplace: 7.14.0; 7.14.1; 10.0.0; 10.0.1; 10.1.0; 10.2.0, y TIBCO Spotfire Server: 7.14.0; 10.0.0; 10.0.1; 10.1.0; 10.2.0.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-12 CVE Reserved
- 2019-05-14 CVE Published
- 2024-05-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Spotfire Analytics Platform For Aws Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" | 7.14.0 Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "7.14.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Analytics Platform For Aws Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" | 7.14.1 Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "7.14.1" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Analytics Platform For Aws Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" | 10.0.0 Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "10.0.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Analytics Platform For Aws Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" | 10.0.1 Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "10.0.1" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Analytics Platform For Aws Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" | 10.1.0 Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "10.1.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Analytics Platform For Aws Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" | 10.2.0 Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "10.2.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Server Search vendor "Tibco" for product "Spotfire Server" | 7.14.0 Search vendor "Tibco" for product "Spotfire Server" and version "7.14.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Server Search vendor "Tibco" for product "Spotfire Server" | 10.0.0 Search vendor "Tibco" for product "Spotfire Server" and version "10.0.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Server Search vendor "Tibco" for product "Spotfire Server" | 10.0.1 Search vendor "Tibco" for product "Spotfire Server" and version "10.0.1" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Server Search vendor "Tibco" for product "Spotfire Server" | 10.1.0 Search vendor "Tibco" for product "Spotfire Server" and version "10.1.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Server Search vendor "Tibco" for product "Spotfire Server" | 10.2.0 Search vendor "Tibco" for product "Spotfire Server" and version "10.2.0" | - |
Affected
|