Security Advisory regarding TIBCO Spotfire

Security Advisory regarding TIBCO Spotfire

book

Article ID: KB0108033

calendar_today

Updated On:

Products Versions
Spotfire Analyst 10.7.0, 10.8.0, 10.9.0, 10.10.0
Spotfire Server 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, and 10.10.1

Description

IBCO Spotfire Stored Cross Site Scripting Vulnerability

  Original release date: September 15, 2020
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains a vulnerability that theoretically allows
  allows a legitimate user to inject scripts. If executed by a victim
  authenticated to the affected system these scripts will be executed at the
  privileges of the victim.


Impact

  The theoretical impact of this vulnerability is that the attacker can execute
  scripts on the affected system of the victim that will execute with the
  privileges of the victim. If the victim has administrative privileges the
  attacker’s injected scripts would allow the attacker to access all files,
  stop/start some services and change limited configuration settings.

  CVSS v3 Base Score: 8.2 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L)

Environment

Systems Affected TIBCO Spotfire Analyst versions 10.7.0, 10.8.0, 10.9.0, and 10.10.0 TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, and 10.10.1 TIBCO Spotfire Desktop versions 10.7.0, 10.8.0, 10.9.0, and 10.10.0 TIBCO Spotfire Server versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, and 10.10.1 The following component is affected: * Spotfire client

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO Spotfire Analyst versions 10.7.0, 10.8.0, 10.9.0, and 10.10.0 update
    to version 10.10.1 or higher

  TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.7.0,
    10.8.0, 10.8.1, 10.9.0, 10.10.0, and 10.10.1 update to version 10.10.2 or
    higher

  TIBCO Spotfire Desktop versions 10.7.0, 10.8.0, 10.9.0, and 10.10.0 update
    to version 10.10.1 or higher

  TIBCO Spotfire Server versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 10.10.0, and
    10.10.1 update to version 10.10.2 or higher
 

Issue/Introduction

Security Advisory regarding TIBCO Spotfire Stored Cross Site Scripting Vulnerability

Additional Information

  http://www.tibco.com/services/support/advisories
  CVE-2020-9416