TIBCO Spotfire Products Multiple Remote Vulnerabilities
BID:49404
Info
TIBCO Spotfire Products Multiple Remote Vulnerabilities
| Bugtraq ID: | 49404 |
| Class: | Unknown |
| CVE: |
CVE-2011-3132 CVE-2011-3133 CVE-2011-3134 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2011 12:00AM |
| Updated: | Sep 01 2011 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
TIBCO Spotfire Server 3.3.0 TIBCO Spotfire Server 3.2.0 TIBCO Spotfire Server 3.1.1 TIBCO Spotfire Server 3.1.0 TIBCO Spotfire Server 3.0.1 TIBCO Spotfire Server 3.0.0 TIBCO Spotfire Analytics Server 10.1 |
| Not Vulnerable: |
TIBCO Spotfire Analytics Server 10.1.1 |
Discussion
TIBCO Spotfire Products Multiple Remote Vulnerabilities
TIBCO Spotfire products are prone to multiple remote vulnerabilities, including:
1. An unspecified cross-site scripting vulnerability.
2. An unspecified SQL-injection vulnerability.
3. A session hijacking vulnerability.
Exploiting these issues could allow an attacker to hijack another users session, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
Spotfire Analytics Server versions prior to 10.1.1
Spotfire Server versions 3.0.0, 3.0.1, 3.1.0, 3.1.1, 3.2.0, and 3.3.0.
TIBCO Spotfire products are prone to multiple remote vulnerabilities, including:
1. An unspecified cross-site scripting vulnerability.
2. An unspecified SQL-injection vulnerability.
3. A session hijacking vulnerability.
Exploiting these issues could allow an attacker to hijack another users session, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
Spotfire Analytics Server versions prior to 10.1.1
Spotfire Server versions 3.0.0, 3.0.1, 3.1.0, 3.1.1, 3.2.0, and 3.3.0.
Exploit / POC
TIBCO Spotfire Products Multiple Remote Vulnerabilities
An attacker can exploit some of these issues with a browser. To exploit cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit some of these issues with a browser. To exploit cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TIBCO Spotfire Products Multiple Remote Vulnerabilities
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
TIBCO Spotfire Products Multiple Remote Vulnerabilities
References:
References:
- TIBCO Homepage (TIBCO)
- TIBCO Spotfire vulnerabilities (TIBCO)