TIBCO Spotfire Products Unspecified Information Disclosure Vulnerability
BID:52380
Info
TIBCO Spotfire Products Unspecified Information Disclosure Vulnerability
| Bugtraq ID: | 52380 |
| Class: | Unknown |
| CVE: |
CVE-2012-0690 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2012 12:00AM |
| Updated: | Mar 09 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
TIBCO Spotfire Web Player 4.0.1 TIBCO Spotfire Web Player 3.3.1 TIBCO Spotfire Web Player 3.2.1 TIBCO Spotfire Web Player 3.1 TIBCO Spotfire Server 3.3.0 TIBCO Spotfire Server 3.2.0 TIBCO Spotfire Server 3.1.1 TIBCO Spotfire Server 3.1.0 TIBCO Spotfire Server 3.0.1 TIBCO Spotfire Server 3.0.0 TIBCO Spotfire Professional 4.0.1 TIBCO Spotfire Professional 3.3.1 TIBCO Spotfire Professional 3.2.1 TIBCO Spotfire Professional 3.1 TIBCO Spotfire Automation Services 4.0.1 TIBCO Spotfire Automation Services 3.3.1 TIBCO Spotfire Automation Services 3.2.1 TIBCO Spotfire Automation Services 3.1 TIBCO Spotfire Analytics Server 10.1.1 TIBCO Spotfire Analytics Server 10.1 |
| Not Vulnerable: |
TIBCO Spotfire Web Player 4.0.2 TIBCO Spotfire Web Player 3.3.2 TIBCO Spotfire Web Player 3.2.2 TIBCO Spotfire Web Player 3.1.1 TIBCO Spotfire Server 3.3.3 TIBCO Spotfire Server 3.2.2 TIBCO Spotfire Server 3.1.3 TIBCO Spotfire Professional 4.0.2 TIBCO Spotfire Professional 3.3.2 TIBCO Spotfire Professional 3.2.2 TIBCO Spotfire Professional 3.1.1 TIBCO Spotfire Automation Services 4.0.2 TIBCO Spotfire Automation Services 3.3.2 TIBCO Spotfire Automation Services 3.2.2 TIBCO Spotfire Automation Services 3.1.1 TIBCO Spotfire Analytics Server 10.1.2 |
Discussion
TIBCO Spotfire Products Unspecified Information Disclosure Vulnerability
TIBCO Spotfire products are prone to an unspecified information-disclosure vulnerability.
Attackers can exploit this issue to harvest sensitive information that may lead to further attacks.
The following components are affected:
TIBCO Spotfire Web Application
TIBCO Spotfire Web Player Application
TIBCO Spotfire Automation Services Application
TIBCO Spotfire Analytics Client Application
The following products are affected:
TIBCO Spotfire Analytics Server below 10.1.2
TIBCO Spotfire Server below 3.1.3
TIBCO Spotfire Server 3.2.X versions below 3.2.2
TIBCO Spotfire Server 3.3.X versions below 3.3.3
TIBCO Spotfire Web Player below 3.1.1
TIBCO Spotfire Web Player 3.2.X versions below 3.2.2
TIBCO Spotfire Web Player 3.3.X versions below 3.3.2
TIBCO Spotfire Web Player 4.0.X versions below 4.0.2
TIBCO Spotfire Automation Services below 3.1.1
TIBCO Spotfire Automation Services 3.2.X versions below 3.2.2
TIBCO Spotfire Automation Services 3.3.X versions below 3.3.2
TIBCO Spotfire Automation Services 4.0.X versions below 4.0.2
TIBCO Spotfire Professional below 3.1.1
TIBCO Spotfire Professional 3.2.x versions below 3.2.2
TIBCO Spotfire Professional 3.3.x versions below 3.3.2
TIBCO Spotfire Professional 4.0.x versions below 4.0.2
TIBCO Spotfire products are prone to an unspecified information-disclosure vulnerability.
Attackers can exploit this issue to harvest sensitive information that may lead to further attacks.
The following components are affected:
TIBCO Spotfire Web Application
TIBCO Spotfire Web Player Application
TIBCO Spotfire Automation Services Application
TIBCO Spotfire Analytics Client Application
The following products are affected:
TIBCO Spotfire Analytics Server below 10.1.2
TIBCO Spotfire Server below 3.1.3
TIBCO Spotfire Server 3.2.X versions below 3.2.2
TIBCO Spotfire Server 3.3.X versions below 3.3.3
TIBCO Spotfire Web Player below 3.1.1
TIBCO Spotfire Web Player 3.2.X versions below 3.2.2
TIBCO Spotfire Web Player 3.3.X versions below 3.3.2
TIBCO Spotfire Web Player 4.0.X versions below 4.0.2
TIBCO Spotfire Automation Services below 3.1.1
TIBCO Spotfire Automation Services 3.2.X versions below 3.2.2
TIBCO Spotfire Automation Services 3.3.X versions below 3.3.2
TIBCO Spotfire Automation Services 4.0.X versions below 4.0.2
TIBCO Spotfire Professional below 3.1.1
TIBCO Spotfire Professional 3.2.x versions below 3.2.2
TIBCO Spotfire Professional 3.3.x versions below 3.3.2
TIBCO Spotfire Professional 4.0.x versions below 4.0.2
Solution / Fix
TIBCO Spotfire Products Unspecified Information Disclosure Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
TIBCO Spotfire Products Unspecified Information Disclosure Vulnerability
References:
References: