CVE-2022-30579
TIBCO Spotfire Server Blind SSRF vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.
El componente Web Player de TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace y TIBCO Spotfire Server contiene una vulnerabilidad difícil de explotar que permite a un atacante poco privilegiado y acceso a la red ejecutar un ataque de tipo Server Side Request Forgery (SSRF) ciego en el sistema afectado. Las versiones afectadas son TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versión 12.0.0 y TIBCO Spotfire Server: versión 12.0.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-11 CVE Reserved
- 2022-09-20 CVE Published
- 2024-04-12 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Spotfire Analytics Platform Search vendor "Tibco" for product "Spotfire Analytics Platform" | 12.0.0 Search vendor "Tibco" for product "Spotfire Analytics Platform" and version "12.0.0" | aws_marketplace |
Affected
| ||||||
Tibco Search vendor "Tibco" | Spotfire Server Search vendor "Tibco" for product "Spotfire Server" | 12.0.0 Search vendor "Tibco" for product "Spotfire Server" and version "12.0.0" | - |
Affected
|