CVE-2023-29268
Summary
| CVE | CVE-2023-29268 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-26 18:15:00 UTC |
| Updated | 2023-05-09 01:31:00 UTC |
| Description | The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Spotfire Statistics Services | All | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.5.0 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.6.0 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.6.1 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.6.2 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.7.0 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.8.0 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 11.8.1 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 12.0.0 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 12.0.1 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 12.0.2 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 12.1.0 | All | All | All |
| Application | Tibco | Spotfire Statistics Services | 12.2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.