The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.
References
Link | Resource |
---|---|
https://www.tibco.com/services/support/advisories | Vendor Advisory |
https://www.tibco.com/services/support/advisories | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.tibco.com/services/support/advisories - Vendor Advisory |
18 Oct 2023, 20:30
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CWE | CWE-79 | |
References | (MISC) https://www.tibco.com/services/support/advisories - Vendor Advisory | |
CPE | cpe:2.3:a:tibco:spotfire_server:11.6.3:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:11.7.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.7.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.0.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.6.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.0.2:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.8.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.0.3:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.0.3:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.0.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.6.2:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.1.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.8.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.5.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.6.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:11.6.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.0.5:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:11.8.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.0.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:12.0.4:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.0.4:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.0.2:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.1.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:11.5.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:12.0.1:*:*:*:*:*:*:* |
|
First Time |
Tibco spotfire Analyst
Tibco spotfire Server Tibco |
10 Oct 2023, 23:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-10 23:15
Updated : 2024-11-21 07:50
NVD link : CVE-2023-26220
Mitre link : CVE-2023-26220
CVE.ORG link : CVE-2023-26220
JSON object : View
Products Affected
tibco
- spotfire_server
- spotfire_analyst
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')