Description
The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.

Published: 2023-11-08
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

TIBCO has released updated versions of the affected components which address these issues. Spotfire Analyst versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later Spotfire Server versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later Spotfire for AWS Marketplace version 12.5.0: update to version 14.0.0 or later

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-30046 The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.
History

No history.

Subscriptions

Tibco Spotfire Analyst Spotfire Analytics Platform Spotfire Server
cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-04T15:46:47.013Z

Reserved: 2023-02-20T22:18:23.428Z

Link: CVE-2023-26221

cve-icon Vulnrichment

Updated: 2024-08-02T11:46:23.940Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T20:15:07.313

Modified: 2024-11-21T07:50:56.717

Link: CVE-2023-26221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses