CVE-2019-8987
TIBCO Spotfire Data Science Vulnerable to Persistent Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.
El componente del servidor de la aplicación de TIBCO Data Science for AWS y TIBCO Spotfire Data Science, de TIBCO Software Inc., contiene una vulnerabilidad de Cross-Site Scripting (XSS) persistente que, en teoría, permite que un usuario autenticado obtenga acceso a todas las funcionalidades de la interfaz web disponibles para los usuarios con más privilegios. Las versiones afectadas de los productos de TIBCO Software Inc. son TIBCO Data Science for AWS: versiones hasta e incluyendo la 6.4.0 y TIBCO Spotfire Data Science: versiones hasta e incluyendo la 6.4.0.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-21 CVE Reserved
- 2019-03-26 CVE Published
- 2024-03-19 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Data Science For Aws Search vendor "Tibco" for product "Data Science For Aws" | <= 6.4.0 Search vendor "Tibco" for product "Data Science For Aws" and version " <= 6.4.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Data Science Search vendor "Tibco" for product "Spotfire Data Science" | <= 6.4.0 Search vendor "Tibco" for product "Spotfire Data Science" and version " <= 6.4.0" | - |
Affected
|