// For flags

CVE-2022-30579

TIBCO Spotfire Server Blind SSRF vulnerability

Severity Score

8.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.

El componente Web Player de TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace y TIBCO Spotfire Server contiene una vulnerabilidad difícil de explotar que permite a un atacante poco privilegiado y acceso a la red ejecutar un ataque de tipo Server Side Request Forgery (SSRF) ciego en el sistema afectado. Las versiones afectadas son TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versión 12.0.0 y TIBCO Spotfire Server: versión 12.0.0

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-11 CVE Reserved
  • 2022-09-20 CVE Published
  • 2024-04-12 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tibco
Search vendor "Tibco"
Spotfire Analytics Platform
Search vendor "Tibco" for product "Spotfire Analytics Platform"
12.0.0
Search vendor "Tibco" for product "Spotfire Analytics Platform" and version "12.0.0"
aws_marketplace
Affected
Tibco
Search vendor "Tibco"
Spotfire Server
Search vendor "Tibco" for product "Spotfire Server"
12.0.0
Search vendor "Tibco" for product "Spotfire Server" and version "12.0.0"
-
Affected