CVE-2022-30579
Published on: Not Yet Published
Last Modified on: 09/22/2022 02:32:00 PM UTC
Certain versions of Spotfire Analytics Platform from Tibco contain the following vulnerability:
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.
- CVE-2022-30579 has been assigned by
sec[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO Spotfire Analytics Platform for AWS Marketplace version = 12.0.0
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO Spotfire Server version = 12.0.0
CVSS3 Score: 8.4 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | HIGH | HIGH | LOW |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Advisory | TIBCO Software | web.archive.org text/html Inactive LinkNot Archived |
![]() |
TIBCO Security Advisory: September 20, 2022 - TIBCO Spotfire - CVE-2022-30579 | TIBCO Software | www.tibco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Spotfire Analytics Platform | 12.0.0 | All | All | All |
Application | Tibco | Spotfire Server | 12.0.0 | All | All | All |
- cpe:2.3:a:tibco:spotfire_analytics_platform:12.0.0:*:*:*:*:aws_marketplace:*:*:
- cpe:2.3:a:tibco:spotfire_server:12.0.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-30579 : The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Market… twitter.com/i/web/status/1… | 2022-09-20 19:00:45 |
![]() |
CVE-2022-30579 | 2022-09-20 20:38:44 |