CVE-2023-26221
TIBCO Spotfire Insufficiently Protected Credential vulnerability
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
08 nov 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Productos afectados
TIBCO Software Inc. · Spotfire AnalystTIBCO Software Inc. · Spotfire for AWS MarketplaceTIBCO Software Inc. · Spotfire Server¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →