CVE-2018-5436
Summary
| CVE | CVE-2018-5436 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-27 16:29:00 UTC |
| Updated | 2019-10-09 23:41:00 UTC |
| Description | The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Spotfire Analytics Platform For Aws | All | All | All | All |
| Application | Tibco | Spotfire Server | 7.10.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.11.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.12.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.9.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.10.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.11.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.12.0 | All | All | All |
| Application | Tibco | Spotfire Server | 7.9.0 | All | All | All |
| Application | Tibco | Spotfire Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| TIBCO Security Advisory: June 26, 2018 - TIBCO Spotfire - 2018-5436 | TIBCO Software | CONFIRM | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.