QID 375937

Date Published: 2021-10-06

QID 375937: TIBCO Spotfire Analyst Cross-Site Scripting (XSS) Vulnerability (Tibco-security-advisory-march-9-2021-tibco-spotfire)

The component listed above contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker.

Affected Products:
TIBCO Spotfire Analyst versions 10.3.3 and below
TIBCO Spotfire Analyst versions 10.10.0, 10.10.1, and 10.10.2
TIBCO Spotfire Analyst versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0

The impact of this vulnerability includes the theoretical possibility that an attacker gains access, including potentially administrative access, to the affected system.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to refer to Tibco-security-advisory-march-9-2021-tibco-spotfire for information pertaining to remediating this vulnerability.
    Vendor References

    CVEs related to QID 375937

    Software Advisories
    Advisory ID Software Component Link
    Tibco-security-advisory-march-9-2021-tibco-spotfire URL Logo www.tibco.com/support/advisories/2021/03/tibco-security-advisory-march-9-2021-tibco-spotfire