Security Advisory for TIBCO Spotfire Server

Security Advisory for TIBCO Spotfire Server

book

Article ID: KB0108141

calendar_today

Updated On:

Products Versions
Spotfire Server -
Not Applicable -

Description

Description:

TIBCO Spotfire Server vulnerabilities

Original release date: September 03, 2014
Last revised: --
Source: TIBCO Software Inc.


Systems Affected

  • TIBCO Spotfire Server 3.3 and earlier
  • TIBCO Spotfire Server 4.5.0 and 4.5.1
  • TIBCO Spotfire Server 5.0.0, 5.0.1, and 5.0.2
  • TIBCO Spotfire Server 5.5.0 and 5.5.1
  • TIBCO Spotfire Server 6.0.0, 6.0.1, and 6.0.2
  • TIBCO Spotfire Server 6.5.0


The following components are affected:

  • TIBCO Spotfire Server Authentication Module


Description

The TIBCO Spotfire components listed above contain a critical vulnerability
which could allow an escalation of privilege.

TIBCO has released updated versions of the affected software products
which address these issues. TIBCO strongly recommends sites running the
affected components install the applicable update as described below.


Impact

The impact of these vulnerabilities may include unprivileged information disclosure and
information modification.


Solution

For each affected system, update to the corresponding software versions:

  • TIBCO Spotfire Server 4.5.X version 4.5.2 or higher
  • TIBCO Spotfire Server 5.0.X version 5.0.3 or higher
  • TIBCO Spotfire Server 5.5.X version 5.5.2 or higher
  • TIBCO Spotfire Server 6.0.X version 6.0.3 or higher
  • TIBCO Spotfire Server 6.5.X version 6.5.1 or higher



References

http://www.tibco.com/mk/advisory.jsp
CVE: CVE-2014-5285

Environment

All Supported Platforms

Issue/Introduction

Security Advisory for TIBCO Spotfire Server

Additional Information

http://www.tibco.com/mk/advisory.jsp
CVE: CVE-2014-5285