{"api_version":"1","generated_at":"2026-07-23T06:06:10+00:00","cve":"CVE-2017-5527","urls":{"html":"https://cve.report/CVE-2017-5527","api":"https://cve.report/api/cve/CVE-2017-5527.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5527","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5527"},"summary":{"title":"TIBCO Spotfire injection vulnerabilities","description":"TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.","state":"PUBLISHED","assigner":"tibco","published_at":"2017-05-09 20:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-89","SQL injection attack"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.0","source":"security@tibco.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.0","source":"CNA","type":"DECLARED","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:L/S:U/UI:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:L/S:U/UI:N","version":"3.0"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.tibco.com/support/advisories/2017/05/tibco-security-advisory-may-9-2017-tibco-spotfire-server","name":"http://www.tibco.com/support/advisories/2017/05/tibco-security-advisory-may-9-2017-tibco-spotfire-server","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"TIBCO Security Advisory: May 9, 2017 - TIBCO Spotfire® Server | TIBCO Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/98398","name":"http://www.securityfocus.com/bid/98398","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple TIBCO Products CVE-2017-5527 Multiple Unspecified SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5527","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5527","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Server","version":"affected 7.0.0","platforms":[]},{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Server","version":"affected 7.0.1","platforms":[]},{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Server","version":"affected 7.5.0","platforms":[]},{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Server","version":"affected 7.6.0","platforms":[]},{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Server","version":"affected 7.7.0","platforms":[]},{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Server","version":"affected 7.8.0","platforms":[]},{"source":"CNA","vendor":"TIBCO Software Inc.","product":"TIBCO Spotfire Analytics Platform for AWS Marketplace","version":"affected 7.8.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"7.8.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_analytics_platform_for_aws","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_server","cpe6":"7.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_server","cpe6":"7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_server","cpe6":"7.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_server","cpe6":"7.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_server","cpe6":"7.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"spotfire_server","cpe6":"7.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T15:04:15.132Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.tibco.com/support/advisories/2017/05/tibco-security-advisory-may-9-2017-tibco-spotfire-server"},{"name":"98398","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/98398"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"TIBCO Spotfire Server","vendor":"TIBCO Software Inc.","versions":[{"status":"affected","version":"7.0.0"},{"status":"affected","version":"7.0.1"},{"status":"affected","version":"7.5.0"},{"status":"affected","version":"7.6.0"},{"status":"affected","version":"7.7.0"},{"status":"affected","version":"7.8.0"}]},{"product":"TIBCO Spotfire Analytics Platform for AWS Marketplace","vendor":"TIBCO Software Inc.","versions":[{"status":"affected","version":"7.8.0"}]}],"datePublic":"2017-05-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks."}],"metrics":[{"cvssV3_0":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:L/S:U/UI:N","version":"3.0"}}],"problemTypes":[{"descriptions":[{"description":"SQL injection attack","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-22T09:57:01.000Z","orgId":"4f830c72-39e4-45f6-a99f-78cc01ae04db","shortName":"tibco"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.tibco.com/support/advisories/2017/05/tibco-security-advisory-may-9-2017-tibco-spotfire-server"},{"name":"98398","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/98398"}],"title":"TIBCO Spotfire injection vulnerabilities","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@tibco.com","DATE_PUBLIC":"2017-05-09T09:00:00-07","ID":"CVE-2017-5527","STATE":"PUBLIC","TITLE":"TIBCO Spotfire injection vulnerabilities"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"TIBCO Spotfire Server","version":{"version_data":[{"version_value":"7.0.0"},{"version_value":"7.0.1"},{"version_value":"7.5.0"},{"version_value":"7.6.0"},{"version_value":"7.7.0"},{"version_value":"7.8.0"}]}},{"product_name":"TIBCO Spotfire Analytics Platform for AWS Marketplace","version":{"version_data":[{"version_value":"7.8.0"}]}}]},"vendor_name":"TIBCO Software Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks."}]},"impact":{"cvssv3":{"BM":{"A":"N","AC":"L","AV":"N","C":"L","I":"N","PR":"L","S":"U","UI":"N"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"SQL injection attack"}]}]},"references":{"reference_data":[{"name":"http://www.tibco.com/support/advisories/2017/05/tibco-security-advisory-may-9-2017-tibco-spotfire-server","refsource":"CONFIRM","url":"http://www.tibco.com/support/advisories/2017/05/tibco-security-advisory-may-9-2017-tibco-spotfire-server"},{"name":"98398","refsource":"BID","url":"http://www.securityfocus.com/bid/98398"}]}}}},"cveMetadata":{"assignerOrgId":"4f830c72-39e4-45f6-a99f-78cc01ae04db","assignerShortName":"tibco","cveId":"CVE-2017-5527","datePublished":"2017-05-09T20:00:00.000Z","dateReserved":"2017-01-19T00:00:00.000Z","dateUpdated":"2024-09-16T19:46:16.352Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-09 20:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-89","SQL injection attack"],"metrics":{"cvssMetricV30":[{"source":"security@tibco.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:*:*:*:*:*:*:*:*","versionEndIncluding":"7.8.0","matchCriteriaId":"1614C09A-D958-4F03-AAC7-C84D4D783688"},{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_server:7.0.0:*:*:*:*:*:*:*","matchCriteriaId":"84EC1E4C-EA97-4892-BD26-23690194F693"},{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_server:7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"C801DEF3-64D4-4FE0-A990-C59B2B1F1CD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_server:7.5.0:*:*:*:*:*:*:*","matchCriteriaId":"DC043E53-0A6D-4CB9-A54F-459561A3ADCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_server:7.6.0:*:*:*:*:*:*:*","matchCriteriaId":"9BFD4F32-E3FA-46BC-B927-C0333C27B6F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_server:7.7.0:*:*:*:*:*:*:*","matchCriteriaId":"4FABB2EC-0B87-4C03-812D-CCF5DFD29CC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:tibco:spotfire_server:7.8.0:*:*:*:*:*:*:*","matchCriteriaId":"C0DEA557-475A-451E-B958-A15B6E7A5E71"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5527","Ordinal":"1","Title":"TIBCO Spotfire injection vulnerabilities","CVE":"CVE-2017-5527","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5527","Ordinal":"1","NoteData":"TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.","Type":"Description","Title":"TIBCO Spotfire injection vulnerabilities"},{"CveYear":"2017","CveId":"5527","Ordinal":"2","NoteData":"2017-05-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5527","Ordinal":"3","NoteData":"2017-05-22","Type":"Other","Title":"Modified"}]}}}