Search

Find a vulnerability

Search criteria

    464 vulnerabilities by TIBCO

    CVE-2026-4034 (GCVE-0-2026-4034)

    Vulnerability from nvd – Published: 2026-09-29 13:05 – Updated: 2026-09-29 14:33
    VLAI
    Title
    TIBCO Administrator Injection Vulnerability
    Summary
    Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 14:32 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    Tibco Administrator Affected: 0 , ≤ 5.13.0 (Hotfix)
    Create a notification for this product.
    Date Public
    2026-09-29 12:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-4034",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T14:32:53.187251Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-74",
                    "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T14:33:25.093Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Administrator",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThanOrEqual": "5.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Hotfix"
                }
              ]
            }
          ],
          "datePublic": "2026-09-29T12:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Injection Vulnerability in Tibco Administrator version 5.13.0 \u0026amp; prior allows\u0026nbsp;an authenticated user to submit specially crafted input through the web-based administration console."
                }
              ],
              "value": "Injection Vulnerability in Tibco Administrator version 5.13.0 \u0026 prior allows\u00a0an authenticated user to submit specially crafted input through the web-based administration console."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T13:05:18.262Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-september-29-2026-tibco-administrator-cve-2026-4034-r229/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO Administrator Injection Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2026-4034",
        "datePublished": "2026-09-29T13:05:18.262Z",
        "dateReserved": "2026-03-12T02:01:53.803Z",
        "dateUpdated": "2026-09-29T14:33:25.093Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-3912 (GCVE-0-2026-3912)

    Vulnerability from nvd – Published: 2026-03-24 20:44 – Updated: 2026-03-25 13:33
    VLAI
    Title
    TIBCO ActiveMatrix BusinessWorks Injection Vulnerability
    Summary
    Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-25 13:33 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Tibco ActiveMatrix BusinessWorks Affected: 6.12.0 , < HF1 (Hotfix)
    Affected: 6.11.0 , < HF4 (Hotfix)
    Affected: 6.10.0 , < HF6 (Hotfix)
    Affected: 6.9.1 , < HF8 (Hotfix)
    Create a notification for this product.
    Tibco Enterprise Administrator Affected: 2.4.3 , < HF2 (Hotfix)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-3912",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-25T13:33:20.540890Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-25T13:33:23.189Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ActiveMatrix BusinessWorks",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThan": "HF1",
                  "status": "affected",
                  "version": "6.12.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "HF4",
                  "status": "affected",
                  "version": "6.11.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "HF6",
                  "status": "affected",
                  "version": "6.10.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "HF8",
                  "status": "affected",
                  "version": "6.9.1",
                  "versionType": "Hotfix"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Administrator",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThan": "HF2",
                  "status": "affected",
                  "version": "2.4.3",
                  "versionType": "Hotfix"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cspan\u003eInjection vulnerabilities due to validation/sanitisation of user-supplied input in\u0026nbsp;ActiveMatrix BusinessWorks and\u0026nbsp;Enterprise Administrator allows\u0026nbsp;information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.\u003c/span\u003e\u003c/div\u003e"
                }
              ],
              "value": "Injection vulnerabilities due to validation/sanitisation of user-supplied input in\u00a0ActiveMatrix BusinessWorks and\u00a0Enterprise Administrator allows\u00a0information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-24T20:44:06.781Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-24-2026-tibco-activematrix-businessworks-cve-2026-3912-r227/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO ActiveMatrix BusinessWorks Injection Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2026-3912",
        "datePublished": "2026-03-24T20:44:06.781Z",
        "dateReserved": "2026-03-11T04:50:22.400Z",
        "dateUpdated": "2026-03-25T13:33:23.189Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-3207 (GCVE-0-2026-3207)

    Vulnerability from nvd – Published: 2026-03-17 18:20 – Updated: 2026-03-17 18:49
    VLAI
    Title
    TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability
    Summary
    Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-17 18:48 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    Impacted products
    Vendor Product Version
    TIBCO TIBCO BPM Enterprise Affected: 4.3 , < 5 (Patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-3207",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-17T18:48:39.829764Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-17T18:49:27.505Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Java Management Extensions (JMX)"
              ],
              "product": "TIBCO BPM Enterprise",
              "vendor": "TIBCO",
              "versions": [
                {
                  "lessThan": "5",
                  "status": "affected",
                  "version": "4.3",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Configuration issue\u0026nbsp;in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access."
                }
              ],
              "value": "Configuration issue\u00a0in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-17T18:20:16.934Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-17-2026-tibco-bpm-enterprise-cve-2026-3207-r226/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2026-3207",
        "datePublished": "2026-03-17T18:20:16.934Z",
        "dateReserved": "2026-02-25T15:39:30.380Z",
        "dateUpdated": "2026-03-17T18:49:27.505Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-3115 (GCVE-0-2025-3115)

    Vulnerability from nvd – Published: 2025-04-09 18:12 – Updated: 2025-11-11 11:47
    VLAI
    Title
    Spotfire Data Function Vulnerability
    Summary
    Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-09 18:28 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Spotfire Spotfire Statistics Services Affected: 14 , < 14.0.7 (Patch)
    Affected: 14.1.0 (Patch)
    Affected: 14.2.0 (Patch)
    Affected: 14.3.0 (Patch)
    Affected: 14.4.0 (Patch)
    Affected: 14.4.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Analyst Affected: 14.0 , < 14.0.6 (Patch)
    Affected: 14.1.0 (Patch)
    Affected: 14.2.0 (Patch)
    Affected: 14.3.0 (Patch)
    Affected: 14.4.0 (Patch)
    Affected: 14.4.1 (Patch)
    Create a notification for this product.
    Spotfire Deployment Kit used in Spotfire Server Affected: 14.0 , < 14.0.7 (Patch)
    Affected: 14.1.0 (Patch)
    Affected: 14.2.0 (Patch)
    Affected: 14.3.0 (Patch)
    Affected: 14.4.0 (Patch)
    Affected: 14.4.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Desktop Affected: 14.4 , < 14.4.2 (Patch)
    Create a notification for this product.
    Spotfire Spotfire for AWS Marketplace Unknown: 14.4 , < 14.4.2 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Enterprise Runtime for R - Server Edition Affected: 1.17 , < 1.17.7 (Patch)
    Affected: 1.18.0 (Patch)
    Affected: 1.19.0 (Patch)
    Affected: 1.20.0 (Patch)
    Affected: 1.21.0 (Patch)
    Affected: 1.21.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Service for Python Affected: 1.17 , < 1.17.7 (Patch)
    Affected: 1.18.0 , ≤ 1.21.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Service for R Affected: 1.17 , < 1.17.7 (Patch)
    Affected: 1.18.0 , ≤ 1.21.1 (Patch)
    Create a notification for this product.
    Date Public
    2025-04-08 16:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-3115",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-09T18:28:35.698097Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-09T18:29:39.691Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire Statistics Services",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.0.7",
                  "status": "affected",
                  "version": "14",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.1.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.3.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Analyst",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.0.6",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.1.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.3.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Deployment Kit used in Spotfire Server",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.0.7",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.1.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.3.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Desktop",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.4.2",
                  "status": "affected",
                  "version": "14.4",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire for AWS Marketplace",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.4.2",
                  "status": "unknown",
                  "version": "14.4",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Enterprise Runtime for R - Server Edition",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "1.17.7",
                  "status": "affected",
                  "version": "1.17",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.18.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.19.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.20.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.21.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.21.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Service for Python",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "1.17.7",
                  "status": "affected",
                  "version": "1.17",
                  "versionType": "Patch"
                },
                {
                  "lessThanOrEqual": "1.21.1",
                  "status": "affected",
                  "version": "1.18.0",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Service for R",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "1.17.7",
                  "status": "affected",
                  "version": "1.17",
                  "versionType": "Patch"
                },
                {
                  "lessThanOrEqual": "1.21.1",
                  "status": "affected",
                  "version": "1.18.0",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "datePublic": "2025-04-08T16:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\n\n\u003cstrong\u003eInjection Vulnerabilities: \u003c/strong\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAttackers can inject malicious code, potentially gaining control over the system executing these functions.\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution\u003c/span\u003e\n\n\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.\nAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-11T11:47:58.064Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3115-r3485/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Spotfire Data Function Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2025-3115",
        "datePublished": "2025-04-09T18:12:28.348Z",
        "dateReserved": "2025-04-02T10:56:03.148Z",
        "dateUpdated": "2025-11-11T11:47:58.064Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-3325 (GCVE-0-2024-3325)

    Vulnerability from nvd – Published: 2024-07-10 17:02 – Updated: 2024-08-01 20:05
    VLAI
    Title
    JasperReports Server Driver upload vulnerability
    Summary
    Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-10 19:38 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    Jaspersoft JasperReport Servers Affected: 8.0.4 , ≤ 9.0.0 (Patch)
    Create a notification for this product.
    tibco jasperreports_server Affected: 8.0.4 , ≤ 9.0.0 (custom)
        cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jasperreports_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "9.0.0",
                    "status": "affected",
                    "version": "8.0.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3325",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-10T19:38:52.601530Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-269",
                    "description": "CWE-269 Improper Privilege Management",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-11T17:45:36.574Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.439Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-july-9-2024-jasperreports-server-cve-2024-3325-r4/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "JasperReport Servers",
              "vendor": "Jaspersoft",
              "versions": [
                {
                  "lessThanOrEqual": "9.0.0",
                  "status": "affected",
                  "version": "8.0.4",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Jaspersoft JasperReport Servers.\u003cp\u003eThis issue affects JasperReport Servers: from 8.0.4 through 9.0.0.\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-10T17:02:14.138Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-july-9-2024-jasperreports-server-cve-2024-3325-r4/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "JasperReports Server Driver upload vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3325",
        "datePublished": "2024-07-10T17:02:14.138Z",
        "dateReserved": "2024-04-04T17:01:26.198Z",
        "dateUpdated": "2024-08-01T20:05:08.439Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3330 (GCVE-0-2024-3330)

    Vulnerability from nvd – Published: 2024-06-27 18:37 – Updated: 2024-08-01 20:05
    VLAI
    Title
    Spotfire Remote Code Execution Vulnerability
    Summary
    Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-02 19:33 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    Spotfire Spotfire Analyst Affected: 12.0.9 , ≤ 12.5.0 (patch)
    Affected: 14.0 , ≤ 14.0.2 (patch)
    Create a notification for this product.
    Spotfire Spotfire Server Affected: 12.0.10 , ≤ 12.5.0 (patch)
    Affected: 14.0 , ≤ 14.0.3 (patch)
    Affected: 14.2.0 , ≤ 14.3.0 (patch)
    Create a notification for this product.
    Spotfire Spotfire for AWS Marketplace Affected: 14.0 , < 14.3.0 (patch)
    Create a notification for this product.
    tibco spotfire_analyst Affected: 12.1.0
    Affected: 12.1.1
    Affected: 12.2.0
    Affected: 12.3.0
    Affected: 12.4.0
    Affected: 12.5.0
    Affected: 14.0.0
    Affected: 14.0.1
    Affected: 14.0.2
    Affected: 14.1.0
    Affected: 14.2.0
    Affected: 14.3.0
        cpe:2.3:a:tibco:spotfire_analyst:12.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.1.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.3.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.0.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.0.2:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_server Affected: 12.1.0
    Affected: 12.1.1
    Affected: 12.2.0
    Affected: 12.3.0
    Affected: 12.4.0
    Affected: 12.5.0
    Affected: 14.0.0
    Affected: 14.0.1
    Affected: 14.0.2
    Affected: 14.0.3
    Affected: 14.2.0
    Affected: 14.3.0
        cpe:2.3:a:tibco:spotfire_server:12.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.1.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.3.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.2:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.3:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_analytics_platform_for_aws Affected: 0 , ≤ 14.3.0 (custom)
        cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:-:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_analyst Affected: 0 , ≤ 12.0.9 (custom)
        cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_server Affected: 0 , ≤ 12.0.10 (custom)
        cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-26 06:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_analyst:12.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.1.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.3.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.4.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.5.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.0.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.0.2:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_analyst",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.1.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.1.1"
                  },
                  {
                    "status": "affected",
                    "version": "12.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.3.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.4.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.5.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.1"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.2"
                  },
                  {
                    "status": "affected",
                    "version": "14.1.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.3.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_server:12.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.1.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.3.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.4.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.5.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.2:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.1.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.1.1"
                  },
                  {
                    "status": "affected",
                    "version": "12.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.3.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.4.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.5.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.1"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.2"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.3"
                  },
                  {
                    "status": "affected",
                    "version": "14.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.3.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_analytics_platform_for_aws",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "14.3.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_analyst",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "12.0.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "12.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3330",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-02T19:33:08.056282Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-250",
                    "description": "CWE-250 Execution with Unnecessary Privileges",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-22T20:02:22.998Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.410Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3330-r3435/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire Analyst",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThanOrEqual": "12.5.0",
                  "status": "affected",
                  "version": "12.0.9",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "14.0.2",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire Server",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThanOrEqual": "12.5.0",
                  "status": "affected",
                  "version": "12.0.10",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "14.0.3",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "14.3.0",
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire for AWS Marketplace",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.3.0",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2024-06-26T06:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..\u003cp\u003eThis issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker."
                }
              ]
            },
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services."
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-27T18:37:34.119Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3330-r3435/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cb\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Server 12.0.10 and earlier: upgrade to version 12.0.11\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Server 14.2.0, 14.3.0: upgrade to version 14.4.0\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/b\u003e"
                }
              ],
              "value": "*  Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher\n\n\n  *  Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher\n\n\n  *  Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0\n\n\n  *  Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11\n\n\n  *  Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher\n\n\n  *  Spotfire Server 14.2.0, 14.3.0: upgrade to version 14.4.0\n\n\n  *  Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Spotfire Remote Code Execution Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3330",
        "datePublished": "2024-06-27T18:37:34.119Z",
        "dateReserved": "2024-04-04T17:01:54.246Z",
        "dateUpdated": "2024-08-01T20:05:08.410Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-4576 (GCVE-0-2024-4576)

    Vulnerability from nvd – Published: 2024-06-13 06:31 – Updated: 2024-10-27 21:52
    VLAI
    Title
    TIBCO EBX File Inclusion Vulnerability
    Summary
    The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 18:27 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Tibco EBX Affected: 5 , ≤ 9.25 (patch)
    Affected: 6 , ≤ 1.3 HF2 (hotfix)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4576",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T18:27:06.313882Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-27T21:52:02.177Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:47:41.192Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-june-11-2024-tibco-ebx-cve-2024-4576-r215/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EBX",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThanOrEqual": "9.25",
                  "status": "affected",
                  "version": "5",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "1.3 HF2",
                  "status": "affected",
                  "version": "6",
                  "versionType": "hotfix"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThe component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T06:31:41.034Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-june-11-2024-tibco-ebx-cve-2024-4576-r215/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO EBX File Inclusion Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-4576",
        "datePublished": "2024-06-13T06:31:41.034Z",
        "dateReserved": "2024-05-06T22:07:32.628Z",
        "dateUpdated": "2024-10-27T21:52:02.177Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3182 (GCVE-0-2024-3182)

    Vulnerability from nvd – Published: 2024-05-15 18:04 – Updated: 2024-08-01 20:05
    VLAI
    Summary
    Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-11 17:06 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    TIBCO Hawk Affected: 6.2.0 , < 6.2.4 (patch)
    Create a notification for this product.
    tibco hawk Affected: 6.2.0 , < 6.2.4 (custom)
        cpe:2.3:a:tibco:hawk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:hawk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "hawk",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThan": "6.2.4",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3182",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-11T17:06:33.188845Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-200",
                    "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-01T15:15:06.991Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:07.485Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Hawk",
              "vendor": "TIBCO",
              "versions": [
                {
                  "lessThan": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(248, 248, 248);\"\u003eInstall-type password disclosure vulnerability in\u0026nbsp;\u003cspan style=\"background-color: transparent;\"\u003eUniversal Installer including the Silent Installer\u003c/span\u003e in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003euser\u0027s Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Install-type password disclosure vulnerability in\u00a0Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user\u0027s Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-15T18:04:49.997Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3182",
        "datePublished": "2024-05-15T18:04:49.997Z",
        "dateReserved": "2024-04-02T06:27:25.231Z",
        "dateUpdated": "2024-08-01T20:05:07.485Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3323 (GCVE-0-2024-3323)

    Vulnerability from nvd – Published: 2024-04-17 18:53 – Updated: 2024-08-01 20:05
    VLAI
    Title
    Reflected Cross Site Scripting (XSS) vulnerability
    Summary
    Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-22 21:35 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    TIBCO JasperReports Server Affected: 8.0 , < 8.0.4 (Hotfix)
    Affected: 8.2 , < 8.2.0 (Hotfix)
    Create a notification for this product.
    tibco jasperreports_server Affected: 8.0.4
        cpe:2.3:a:tibco:jasperreports_server:8.0.4:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco jasperreports_server Affected: 8.2.0
        cpe:2.3:a:tibco:jasperreports_server:8.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-04-09 16:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:jasperreports_server:8.0.4:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jasperreports_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0.4"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:jasperreports_server:8.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jasperreports_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.2.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3323",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-22T21:35:25.685169Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:31:11.990Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.445Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-april-9-2024-tibco-jasperreports-server-cve-2024-3323-r209/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "UI Request/Response Validation"
              ],
              "product": "JasperReports Server",
              "vendor": "TIBCO",
              "versions": [
                {
                  "lessThan": "8.0.4",
                  "status": "affected",
                  "version": "8.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "8.2.0",
                  "status": "affected",
                  "version": "8.2",
                  "versionType": "Hotfix"
                }
              ]
            }
          ],
          "datePublic": "2024-04-09T16:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross Site Scripting in \n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eUI Request/Response Validation\u003c/span\u003e\n\n in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user\u0027s active session cookie\u0026nbsp;via sending malicious link, enticing the user to interact."
                }
              ],
              "value": "Cross Site Scripting in \n\nUI Request/Response Validation\n\n in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user\u0027s active session cookie\u00a0via sending malicious link, enticing the user to interact."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-17T18:53:21.348Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-april-9-2024-tibco-jasperreports-server-cve-2024-3323-r209/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Reflected Cross Site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3323",
        "datePublished": "2024-04-17T18:53:21.348Z",
        "dateReserved": "2024-04-04T17:01:23.280Z",
        "dateUpdated": "2024-08-01T20:05:08.445Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1138 (GCVE-0-2024-1138)

    Vulnerability from nvd – Published: 2024-03-12 17:30 – Updated: 2025-03-28 18:59
    VLAI
    Title
    TIBCO FTL Privilege Escalation
    Summary
    The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 19:05 UTC
    CWE
    • Successful exploitation of this vulnerability may result in an authenticated but unprivileged user arbitrarily reconfiguring FTL clients attached to the same ftlserver.
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. TIBCO FTL - Enterprise Edition Affected: 0 , ≤ 6.10.1 (semver)
    Create a notification for this product.
    tibco ftl Affected: 0 , ≤ 6.10.1 (semver)
        cpe:2.3:a:tibco:ftl:*:*:*:*:enterprise:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:26:30.563Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-12-2024-tibco-ftl-cve-2024-1138-r207/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:ftl:*:*:*:*:enterprise:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "ftl",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1138",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T19:05:22.151041Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-269",
                    "description": "CWE-269 Improper Privilege Management",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-28T18:59:24.770Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "TIBCO FTL - Enterprise Edition",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "6.10.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe FTL Server component of TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.\u003c/p\u003e"
                }
              ],
              "value": "The FTL Server component of TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Successful exploitation of this vulnerability may result in an authenticated but unprivileged user arbitrarily reconfiguring FTL clients attached to the same ftlserver.",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T17:30:15.100Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-12-2024-tibco-ftl-cve-2024-1138-r207/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO FTL - Enterprise Edition versions 6.10.1 and below: update to version 6.10.2 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO FTL - Enterprise Edition versions 6.10.1 and below: update to version 6.10.2 or later\n\n"
            }
          ],
          "title": "TIBCO FTL Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-1138",
        "datePublished": "2024-03-12T17:30:15.100Z",
        "dateReserved": "2024-01-31T20:35:00.843Z",
        "dateUpdated": "2025-03-28T18:59:24.770Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26222 (GCVE-0-2023-26222)

    Vulnerability from nvd – Published: 2023-11-14 19:29 – Updated: 2024-08-30 14:06
    VLAI
    Title
    TIBCO EBX Cross-site Scripting (XXS) Vulnerability
    Summary
    The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-30 14:06 UTC
    CWE
    • The impact of this vulnerability includes the theoretical possibility resulting in unauthorized ability to update, insert or delete TIBCO EBX® data.
    References
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. TIBCO EBX Affected: 0 , ≤ 5.9.22 (semver)
    Affected: 0 , ≤ 6.0.13 (semver)
    Create a notification for this product.
    TIBCO Software Inc. TIBCO Product and Service Catalog powered by TIBCO EBX Affected: 0 , ≤ 5.0.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.340Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26222",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-30T14:06:41.016491Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-30T14:06:54.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO EBX",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.9.22",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.0.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Product and Service Catalog powered by TIBCO EBX",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Web Application component of TIBCO Software Inc.\u0027s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.\u0027s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.\u003c/p\u003e"
                }
              ],
              "value": "The Web Application component of TIBCO Software Inc.\u0027s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.\u0027s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "The impact of this vulnerability includes the theoretical possibility resulting in unauthorized ability to update, insert or delete TIBCO EBX\u00ae data.",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-11-14T19:29:09.766Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO EBX versions 5.9.22 and below: update to version 5.9.23 or later\u003c/p\u003e\u003cp\u003eTIBCO EBX versions 6.0.13 and below: update to version 6.0.14 or later\u003c/p\u003e\u003cp\u003eTIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below: update to version 5.1.0 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO EBX versions 5.9.22 and below: update to version 5.9.23 or later\n\nTIBCO EBX versions 6.0.13 and below: update to version 6.0.14 or later\n\nTIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below: update to version 5.1.0 or later\n\n"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "TIBCO EBX Cross-site Scripting (XXS) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26222",
        "datePublished": "2023-11-14T19:29:09.766Z",
        "dateReserved": "2023-02-20T22:18:23.428Z",
        "dateUpdated": "2024-08-30T14:06:54.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26221 (GCVE-0-2023-26221)

    Vulnerability from nvd – Published: 2023-11-08 19:44 – Updated: 2024-09-04 15:46
    VLAI
    Title
    TIBCO Spotfire Insufficiently Protected Credential vulnerability
    Summary
    The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-04 15:46 UTC
    CWE
    • CWE-522 - Insufficiently Protected Credentials
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.940Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26221",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-04T15:46:35.719041Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-04T15:46:47.013Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Analyst",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.3.0"
                },
                {
                  "status": "affected",
                  "version": "12.4.0"
                },
                {
                  "status": "affected",
                  "version": "12.5.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Server",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.3.0"
                },
                {
                  "status": "affected",
                  "version": "12.4.0"
                },
                {
                  "status": "affected",
                  "version": "12.5.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire for AWS Marketplace",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Spotfire Connectors component of TIBCO Software Inc.\u0027s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.\u003c/p\u003e"
                }
              ],
              "value": "The Spotfire Connectors component of TIBCO Software Inc.\u0027s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-522",
                  "description": "CWE-522 Insufficiently Protected Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-11-08T19:44:03.634Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\u003c/p\u003e\u003cp\u003eSpotfire for AWS Marketplace version 12.5.0: update to version 14.0.0 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nSpotfire Analyst versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\n\nSpotfire Server versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\n\nSpotfire for AWS Marketplace version 12.5.0: update to version 14.0.0 or later\n\n"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "TIBCO Spotfire Insufficiently Protected Credential vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26221",
        "datePublished": "2023-11-08T19:44:03.634Z",
        "dateReserved": "2023-02-20T22:18:23.428Z",
        "dateUpdated": "2024-09-04T15:46:47.013Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26219 (GCVE-0-2023-26219)

    Vulnerability from nvd – Published: 2023-10-24 21:56 – Updated: 2024-09-11 17:07
    VLAI
    Title
    TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability
    Summary
    The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-11 17:07 UTC
    CWE
    • The impact of this vulnerability includes the theoretical possibility that an attacker could access the message stream of the EMS server, or in the worst case, gain administrative access to the server.
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.339Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26219",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-11T17:07:16.001862Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-11T17:07:46.968Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Hawk",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "6.2.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Hawk Distribution for TIBCO Silver Fabric",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "6.2.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Operational Intelligence Hawk RedTail",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Runtime Agent",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.12.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Hawk Console and Hawk Agent components of TIBCO Software Inc.\u0027s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console\u2019s and Agent\u2019s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.\u0027s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.\u003c/p\u003e"
                }
              ],
              "value": "The Hawk Console and Hawk Agent components of TIBCO Software Inc.\u0027s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console\u2019s and Agent\u2019s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.\u0027s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "The impact of this vulnerability includes the theoretical possibility that an attacker could access the message stream of the EMS server, or in the worst case, gain administrative access to the server.",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-24T21:56:50.294Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO Hawk versions 6.2.2 and below: update to version 6.2.3 or later\u003c/p\u003e\u003cp\u003eTIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below: update to version 6.2.3 or later\u003c/p\u003e\u003cp\u003eTIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below: update to version 7.2.2 or later\u003c/p\u003e\u003cp\u003eTIBCO Runtime Agent versions 5.12.2 and below: update to version 5.12.3 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO Hawk versions 6.2.2 and below: update to version 6.2.3 or later\n\nTIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below: update to version 6.2.3 or later\n\nTIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below: update to version 7.2.2 or later\n\nTIBCO Runtime Agent versions 5.12.2 and below: update to version 5.12.3 or later\n\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26219",
        "datePublished": "2023-10-24T21:56:50.294Z",
        "dateReserved": "2023-02-20T22:18:23.427Z",
        "dateUpdated": "2024-09-11T17:07:46.968Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26220 (GCVE-0-2023-26220)

    Vulnerability from nvd – Published: 2023-10-10 22:06 – Updated: 2024-09-18 16:14
    VLAI
    Title
    TIBCO Spotfire Stored Cross-site Scripting (XSS) vulnerability
    Summary
    The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 16:14 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. Spotfire Analyst Affected: 0 , ≤ 11.4.7 (semver)
    Affected: 11.5.0
    Affected: 11.6.0
    Affected: 11.7.0
    Affected: 11.8.0
    Affected: 12.0.0
    Affected: 12.0.1
    Affected: 12.0.2
    Affected: 12.0.3
    Affected: 12.0.4
    Affected: 12.1.0
    Affected: 12.1.1
    Create a notification for this product.
    TIBCO Software Inc. Spotfire Server Affected: 0 , ≤ 11.4.11 (semver)
    Affected: 11.5.0
    Affected: 11.6.0
    Affected: 11.6.1
    Affected: 11.6.2
    Affected: 11.6.3
    Affected: 11.7.0
    Affected: 11.8.0
    Affected: 11.8.1
    Affected: 12.0.0
    Affected: 12.0.1
    Affected: 12.0.2
    Affected: 12.0.3
    Affected: 12.0.4
    Affected: 12.0.5
    Affected: 12.1.0
    Affected: 12.1.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:24.112Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26220",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T16:14:40.488828Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T16:14:49.914Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Analyst",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "11.4.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "affected",
                  "version": "11.5.0"
                },
                {
                  "status": "affected",
                  "version": "11.6.0"
                },
                {
                  "status": "affected",
                  "version": "11.7.0"
                },
                {
                  "status": "affected",
                  "version": "11.8.0"
                },
                {
                  "status": "affected",
                  "version": "12.0.0"
                },
                {
                  "status": "affected",
                  "version": "12.0.1"
                },
                {
                  "status": "affected",
                  "version": "12.0.2"
                },
                {
                  "status": "affected",
                  "version": "12.0.3"
                },
                {
                  "status": "affected",
                  "version": "12.0.4"
                },
                {
                  "status": "affected",
                  "version": "12.1.0"
                },
                {
                  "status": "affected",
                  "version": "12.1.1"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Server",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "11.4.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "affected",
                  "version": "11.5.0"
                },
                {
                  "status": "affected",
                  "version": "11.6.0"
                },
                {
                  "status": "affected",
                  "version": "11.6.1"
                },
                {
                  "status": "affected",
                  "version": "11.6.2"
                },
                {
                  "status": "affected",
                  "version": "11.6.3"
                },
                {
                  "status": "affected",
                  "version": "11.7.0"
                },
                {
                  "status": "affected",
                  "version": "11.8.0"
                },
                {
                  "status": "affected",
                  "version": "11.8.1"
                },
                {
                  "status": "affected",
                  "version": "12.0.0"
                },
                {
                  "status": "affected",
                  "version": "12.0.1"
                },
                {
                  "status": "affected",
                  "version": "12.0.2"
                },
                {
                  "status": "affected",
                  "version": "12.0.3"
                },
                {
                  "status": "affected",
                  "version": "12.0.4"
                },
                {
                  "status": "affected",
                  "version": "12.0.5"
                },
                {
                  "status": "affected",
                  "version": "12.1.0"
                },
                {
                  "status": "affected",
                  "version": "12.1.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Spotfire Library component of TIBCO Software Inc.\u0027s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.\u003c/p\u003e"
                }
              ],
              "value": "The Spotfire Library component of TIBCO Software Inc.\u0027s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-10T22:06:36.002Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 11.4.7 and below: update to version 11.4.8 or later\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4: update to version 12.0.5 or later\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 11.4.11 and below: update to version 11.4.12 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5: update to version 12.0.6 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nSpotfire Analyst versions 11.4.7 and below: update to version 11.4.8 or later\n\nSpotfire Analyst versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4: update to version 12.0.5 or later\n\nSpotfire Analyst versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\n\nSpotfire Server versions 11.4.11 and below: update to version 11.4.12 or later\n\nSpotfire Server versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5: update to version 12.0.6 or later\n\nSpotfire Server versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\n\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIBCO Spotfire Stored Cross-site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26220",
        "datePublished": "2023-10-10T22:06:36.002Z",
        "dateReserved": "2023-02-20T22:18:23.427Z",
        "dateUpdated": "2024-09-18T16:14:49.914Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26218 (GCVE-0-2023-26218)

    Vulnerability from nvd – Published: 2023-09-29 17:07 – Updated: 2024-09-23 16:26
    VLAI
    Title
    TIBCO Nimbus Reflected Cross-site Scripting (XSS) vulnerabilities
    Summary
    The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.6.0 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-23 16:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. TIBCO Nimbus Affected: 0 , ≤ 10.6.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.316Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26218",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-23T16:26:16.962584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-23T16:26:35.804Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Nimbus",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "10.6.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Web Client component of TIBCO Software Inc.\u0027s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim\u0027s local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s TIBCO Nimbus: versions 10.6.0 and below.\u003c/p\u003e"
                }
              ],
              "value": "The Web Client component of TIBCO Software Inc.\u0027s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim\u0027s local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s TIBCO Nimbus: versions 10.6.0 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-29T17:07:11.618Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO Nimbus versions 10.6.0 and below: update to version 10.6.1 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO Nimbus versions 10.6.0 and below: update to version 10.6.1 or later\n\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIBCO Nimbus Reflected Cross-site Scripting (XSS) vulnerabilities",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26218",
        "datePublished": "2023-09-29T17:07:11.618Z",
        "dateReserved": "2023-02-20T22:18:23.427Z",
        "dateUpdated": "2024-09-23T16:26:35.804Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-4034 (GCVE-0-2026-4034)

    Vulnerability from cvelistv5 – Published: 2026-09-29 13:05 – Updated: 2026-09-29 14:33
    VLAI
    Title
    TIBCO Administrator Injection Vulnerability
    Summary
    Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 14:32 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    Tibco Administrator Affected: 0 , ≤ 5.13.0 (Hotfix)
    Create a notification for this product.
    Date Public
    2026-09-29 12:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-4034",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T14:32:53.187251Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-74",
                    "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T14:33:25.093Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Administrator",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThanOrEqual": "5.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Hotfix"
                }
              ]
            }
          ],
          "datePublic": "2026-09-29T12:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Injection Vulnerability in Tibco Administrator version 5.13.0 \u0026amp; prior allows\u0026nbsp;an authenticated user to submit specially crafted input through the web-based administration console."
                }
              ],
              "value": "Injection Vulnerability in Tibco Administrator version 5.13.0 \u0026 prior allows\u00a0an authenticated user to submit specially crafted input through the web-based administration console."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T13:05:18.262Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-september-29-2026-tibco-administrator-cve-2026-4034-r229/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO Administrator Injection Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2026-4034",
        "datePublished": "2026-09-29T13:05:18.262Z",
        "dateReserved": "2026-03-12T02:01:53.803Z",
        "dateUpdated": "2026-09-29T14:33:25.093Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-3912 (GCVE-0-2026-3912)

    Vulnerability from cvelistv5 – Published: 2026-03-24 20:44 – Updated: 2026-03-25 13:33
    VLAI
    Title
    TIBCO ActiveMatrix BusinessWorks Injection Vulnerability
    Summary
    Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-25 13:33 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Tibco ActiveMatrix BusinessWorks Affected: 6.12.0 , < HF1 (Hotfix)
    Affected: 6.11.0 , < HF4 (Hotfix)
    Affected: 6.10.0 , < HF6 (Hotfix)
    Affected: 6.9.1 , < HF8 (Hotfix)
    Create a notification for this product.
    Tibco Enterprise Administrator Affected: 2.4.3 , < HF2 (Hotfix)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-3912",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-25T13:33:20.540890Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-25T13:33:23.189Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ActiveMatrix BusinessWorks",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThan": "HF1",
                  "status": "affected",
                  "version": "6.12.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "HF4",
                  "status": "affected",
                  "version": "6.11.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "HF6",
                  "status": "affected",
                  "version": "6.10.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "HF8",
                  "status": "affected",
                  "version": "6.9.1",
                  "versionType": "Hotfix"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Administrator",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThan": "HF2",
                  "status": "affected",
                  "version": "2.4.3",
                  "versionType": "Hotfix"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cspan\u003eInjection vulnerabilities due to validation/sanitisation of user-supplied input in\u0026nbsp;ActiveMatrix BusinessWorks and\u0026nbsp;Enterprise Administrator allows\u0026nbsp;information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.\u003c/span\u003e\u003c/div\u003e"
                }
              ],
              "value": "Injection vulnerabilities due to validation/sanitisation of user-supplied input in\u00a0ActiveMatrix BusinessWorks and\u00a0Enterprise Administrator allows\u00a0information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-24T20:44:06.781Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-24-2026-tibco-activematrix-businessworks-cve-2026-3912-r227/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO ActiveMatrix BusinessWorks Injection Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2026-3912",
        "datePublished": "2026-03-24T20:44:06.781Z",
        "dateReserved": "2026-03-11T04:50:22.400Z",
        "dateUpdated": "2026-03-25T13:33:23.189Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-3207 (GCVE-0-2026-3207)

    Vulnerability from cvelistv5 – Published: 2026-03-17 18:20 – Updated: 2026-03-17 18:49
    VLAI
    Title
    TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability
    Summary
    Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-17 18:48 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    Impacted products
    Vendor Product Version
    TIBCO TIBCO BPM Enterprise Affected: 4.3 , < 5 (Patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-3207",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-17T18:48:39.829764Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-17T18:49:27.505Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Java Management Extensions (JMX)"
              ],
              "product": "TIBCO BPM Enterprise",
              "vendor": "TIBCO",
              "versions": [
                {
                  "lessThan": "5",
                  "status": "affected",
                  "version": "4.3",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Configuration issue\u0026nbsp;in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access."
                }
              ],
              "value": "Configuration issue\u00a0in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-17T18:20:16.934Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-17-2026-tibco-bpm-enterprise-cve-2026-3207-r226/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2026-3207",
        "datePublished": "2026-03-17T18:20:16.934Z",
        "dateReserved": "2026-02-25T15:39:30.380Z",
        "dateUpdated": "2026-03-17T18:49:27.505Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-3115 (GCVE-0-2025-3115)

    Vulnerability from cvelistv5 – Published: 2025-04-09 18:12 – Updated: 2025-11-11 11:47
    VLAI
    Title
    Spotfire Data Function Vulnerability
    Summary
    Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-09 18:28 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Spotfire Spotfire Statistics Services Affected: 14 , < 14.0.7 (Patch)
    Affected: 14.1.0 (Patch)
    Affected: 14.2.0 (Patch)
    Affected: 14.3.0 (Patch)
    Affected: 14.4.0 (Patch)
    Affected: 14.4.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Analyst Affected: 14.0 , < 14.0.6 (Patch)
    Affected: 14.1.0 (Patch)
    Affected: 14.2.0 (Patch)
    Affected: 14.3.0 (Patch)
    Affected: 14.4.0 (Patch)
    Affected: 14.4.1 (Patch)
    Create a notification for this product.
    Spotfire Deployment Kit used in Spotfire Server Affected: 14.0 , < 14.0.7 (Patch)
    Affected: 14.1.0 (Patch)
    Affected: 14.2.0 (Patch)
    Affected: 14.3.0 (Patch)
    Affected: 14.4.0 (Patch)
    Affected: 14.4.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Desktop Affected: 14.4 , < 14.4.2 (Patch)
    Create a notification for this product.
    Spotfire Spotfire for AWS Marketplace Unknown: 14.4 , < 14.4.2 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Enterprise Runtime for R - Server Edition Affected: 1.17 , < 1.17.7 (Patch)
    Affected: 1.18.0 (Patch)
    Affected: 1.19.0 (Patch)
    Affected: 1.20.0 (Patch)
    Affected: 1.21.0 (Patch)
    Affected: 1.21.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Service for Python Affected: 1.17 , < 1.17.7 (Patch)
    Affected: 1.18.0 , ≤ 1.21.1 (Patch)
    Create a notification for this product.
    Spotfire Spotfire Service for R Affected: 1.17 , < 1.17.7 (Patch)
    Affected: 1.18.0 , ≤ 1.21.1 (Patch)
    Create a notification for this product.
    Date Public
    2025-04-08 16:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-3115",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-09T18:28:35.698097Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-09T18:29:39.691Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire Statistics Services",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.0.7",
                  "status": "affected",
                  "version": "14",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.1.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.3.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Analyst",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.0.6",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.1.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.3.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Deployment Kit used in Spotfire Server",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.0.7",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.1.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.3.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "14.4.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Desktop",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.4.2",
                  "status": "affected",
                  "version": "14.4",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire for AWS Marketplace",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.4.2",
                  "status": "unknown",
                  "version": "14.4",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Enterprise Runtime for R - Server Edition",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "1.17.7",
                  "status": "affected",
                  "version": "1.17",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.18.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.19.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.20.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.21.0",
                  "versionType": "Patch"
                },
                {
                  "status": "affected",
                  "version": "1.21.1",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Service for Python",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "1.17.7",
                  "status": "affected",
                  "version": "1.17",
                  "versionType": "Patch"
                },
                {
                  "lessThanOrEqual": "1.21.1",
                  "status": "affected",
                  "version": "1.18.0",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Service for R",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "1.17.7",
                  "status": "affected",
                  "version": "1.17",
                  "versionType": "Patch"
                },
                {
                  "lessThanOrEqual": "1.21.1",
                  "status": "affected",
                  "version": "1.18.0",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "datePublic": "2025-04-08T16:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\n\n\u003cstrong\u003eInjection Vulnerabilities: \u003c/strong\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAttackers can inject malicious code, potentially gaining control over the system executing these functions.\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution\u003c/span\u003e\n\n\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.\nAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-11T11:47:58.064Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3115-r3485/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Spotfire Data Function Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2025-3115",
        "datePublished": "2025-04-09T18:12:28.348Z",
        "dateReserved": "2025-04-02T10:56:03.148Z",
        "dateUpdated": "2025-11-11T11:47:58.064Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-3325 (GCVE-0-2024-3325)

    Vulnerability from cvelistv5 – Published: 2024-07-10 17:02 – Updated: 2024-08-01 20:05
    VLAI
    Title
    JasperReports Server Driver upload vulnerability
    Summary
    Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-10 19:38 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    Jaspersoft JasperReport Servers Affected: 8.0.4 , ≤ 9.0.0 (Patch)
    Create a notification for this product.
    tibco jasperreports_server Affected: 8.0.4 , ≤ 9.0.0 (custom)
        cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jasperreports_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "9.0.0",
                    "status": "affected",
                    "version": "8.0.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3325",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-10T19:38:52.601530Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-269",
                    "description": "CWE-269 Improper Privilege Management",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-11T17:45:36.574Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.439Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-july-9-2024-jasperreports-server-cve-2024-3325-r4/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "JasperReport Servers",
              "vendor": "Jaspersoft",
              "versions": [
                {
                  "lessThanOrEqual": "9.0.0",
                  "status": "affected",
                  "version": "8.0.4",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Jaspersoft JasperReport Servers.\u003cp\u003eThis issue affects JasperReport Servers: from 8.0.4 through 9.0.0.\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-10T17:02:14.138Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-july-9-2024-jasperreports-server-cve-2024-3325-r4/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "JasperReports Server Driver upload vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3325",
        "datePublished": "2024-07-10T17:02:14.138Z",
        "dateReserved": "2024-04-04T17:01:26.198Z",
        "dateUpdated": "2024-08-01T20:05:08.439Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3330 (GCVE-0-2024-3330)

    Vulnerability from cvelistv5 – Published: 2024-06-27 18:37 – Updated: 2024-08-01 20:05
    VLAI
    Title
    Spotfire Remote Code Execution Vulnerability
    Summary
    Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-02 19:33 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    Spotfire Spotfire Analyst Affected: 12.0.9 , ≤ 12.5.0 (patch)
    Affected: 14.0 , ≤ 14.0.2 (patch)
    Create a notification for this product.
    Spotfire Spotfire Server Affected: 12.0.10 , ≤ 12.5.0 (patch)
    Affected: 14.0 , ≤ 14.0.3 (patch)
    Affected: 14.2.0 , ≤ 14.3.0 (patch)
    Create a notification for this product.
    Spotfire Spotfire for AWS Marketplace Affected: 14.0 , < 14.3.0 (patch)
    Create a notification for this product.
    tibco spotfire_analyst Affected: 12.1.0
    Affected: 12.1.1
    Affected: 12.2.0
    Affected: 12.3.0
    Affected: 12.4.0
    Affected: 12.5.0
    Affected: 14.0.0
    Affected: 14.0.1
    Affected: 14.0.2
    Affected: 14.1.0
    Affected: 14.2.0
    Affected: 14.3.0
        cpe:2.3:a:tibco:spotfire_analyst:12.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.1.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.3.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:12.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.0.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.0.2:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_server Affected: 12.1.0
    Affected: 12.1.1
    Affected: 12.2.0
    Affected: 12.3.0
    Affected: 12.4.0
    Affected: 12.5.0
    Affected: 14.0.0
    Affected: 14.0.1
    Affected: 14.0.2
    Affected: 14.0.3
    Affected: 14.2.0
    Affected: 14.3.0
        cpe:2.3:a:tibco:spotfire_server:12.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.1.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.3.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:12.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.1:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.2:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.0.3:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:tibco:spotfire_server:14.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_analytics_platform_for_aws Affected: 0 , ≤ 14.3.0 (custom)
        cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:-:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_analyst Affected: 0 , ≤ 12.0.9 (custom)
        cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco spotfire_server Affected: 0 , ≤ 12.0.10 (custom)
        cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-26 06:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_analyst:12.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.1.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.3.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.4.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:12.5.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.0.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.0.2:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_analyst",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.1.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.1.1"
                  },
                  {
                    "status": "affected",
                    "version": "12.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.3.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.4.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.5.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.1"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.2"
                  },
                  {
                    "status": "affected",
                    "version": "14.1.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.3.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_server:12.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.1.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.3.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.4.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:12.5.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.2:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.0.3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:tibco:spotfire_server:14.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.1.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.1.1"
                  },
                  {
                    "status": "affected",
                    "version": "12.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.3.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.4.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.5.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.1"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.2"
                  },
                  {
                    "status": "affected",
                    "version": "14.0.3"
                  },
                  {
                    "status": "affected",
                    "version": "14.2.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.3.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_analytics_platform_for_aws",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "14.3.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_analyst",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "12.0.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "spotfire_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "12.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3330",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-02T19:33:08.056282Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-250",
                    "description": "CWE-250 Execution with Unnecessary Privileges",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-22T20:02:22.998Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.410Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3330-r3435/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire Analyst",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThanOrEqual": "12.5.0",
                  "status": "affected",
                  "version": "12.0.9",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "14.0.2",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire Server",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThanOrEqual": "12.5.0",
                  "status": "affected",
                  "version": "12.0.10",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "14.0.3",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "14.3.0",
                  "status": "affected",
                  "version": "14.2.0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Spotfire for AWS Marketplace",
              "vendor": "Spotfire",
              "versions": [
                {
                  "lessThan": "14.3.0",
                  "status": "affected",
                  "version": "14.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2024-06-26T06:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..\u003cp\u003eThis issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker."
                }
              ]
            },
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services."
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-27T18:37:34.119Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3330-r3435/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cb\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Server 12.0.10 and earlier: upgrade to version 12.0.11\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire Server 14.2.0, 14.3.0: upgrade to version 14.4.0\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(254, 254, 254);\"\u003eSpotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher\u003c/span\u003e\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/b\u003e"
                }
              ],
              "value": "*  Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher\n\n\n  *  Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher\n\n\n  *  Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0\n\n\n  *  Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11\n\n\n  *  Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher\n\n\n  *  Spotfire Server 14.2.0, 14.3.0: upgrade to version 14.4.0\n\n\n  *  Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Spotfire Remote Code Execution Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3330",
        "datePublished": "2024-06-27T18:37:34.119Z",
        "dateReserved": "2024-04-04T17:01:54.246Z",
        "dateUpdated": "2024-08-01T20:05:08.410Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-4576 (GCVE-0-2024-4576)

    Vulnerability from cvelistv5 – Published: 2024-06-13 06:31 – Updated: 2024-10-27 21:52
    VLAI
    Title
    TIBCO EBX File Inclusion Vulnerability
    Summary
    The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 18:27 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Tibco EBX Affected: 5 , ≤ 9.25 (patch)
    Affected: 6 , ≤ 1.3 HF2 (hotfix)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4576",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T18:27:06.313882Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-27T21:52:02.177Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:47:41.192Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-june-11-2024-tibco-ebx-cve-2024-4576-r215/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EBX",
              "vendor": "Tibco",
              "versions": [
                {
                  "lessThanOrEqual": "9.25",
                  "status": "affected",
                  "version": "5",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "1.3 HF2",
                  "status": "affected",
                  "version": "6",
                  "versionType": "hotfix"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThe component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T06:31:41.034Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-june-11-2024-tibco-ebx-cve-2024-4576-r215/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TIBCO EBX File Inclusion Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-4576",
        "datePublished": "2024-06-13T06:31:41.034Z",
        "dateReserved": "2024-05-06T22:07:32.628Z",
        "dateUpdated": "2024-10-27T21:52:02.177Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3182 (GCVE-0-2024-3182)

    Vulnerability from cvelistv5 – Published: 2024-05-15 18:04 – Updated: 2024-08-01 20:05
    VLAI
    Summary
    Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-11 17:06 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    TIBCO Hawk Affected: 6.2.0 , < 6.2.4 (patch)
    Create a notification for this product.
    tibco hawk Affected: 6.2.0 , < 6.2.4 (custom)
        cpe:2.3:a:tibco:hawk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:hawk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "hawk",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThan": "6.2.4",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3182",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-11T17:06:33.188845Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-200",
                    "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-01T15:15:06.991Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:07.485Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Hawk",
              "vendor": "TIBCO",
              "versions": [
                {
                  "lessThan": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(248, 248, 248);\"\u003eInstall-type password disclosure vulnerability in\u0026nbsp;\u003cspan style=\"background-color: transparent;\"\u003eUniversal Installer including the Silent Installer\u003c/span\u003e in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003euser\u0027s Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Install-type password disclosure vulnerability in\u00a0Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user\u0027s Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-15T18:04:49.997Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3182",
        "datePublished": "2024-05-15T18:04:49.997Z",
        "dateReserved": "2024-04-02T06:27:25.231Z",
        "dateUpdated": "2024-08-01T20:05:07.485Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3323 (GCVE-0-2024-3323)

    Vulnerability from cvelistv5 – Published: 2024-04-17 18:53 – Updated: 2024-08-01 20:05
    VLAI
    Title
    Reflected Cross Site Scripting (XSS) vulnerability
    Summary
    Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-22 21:35 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    TIBCO JasperReports Server Affected: 8.0 , < 8.0.4 (Hotfix)
    Affected: 8.2 , < 8.2.0 (Hotfix)
    Create a notification for this product.
    tibco jasperreports_server Affected: 8.0.4
        cpe:2.3:a:tibco:jasperreports_server:8.0.4:*:*:*:*:*:*:*
    Create a notification for this product.
    tibco jasperreports_server Affected: 8.2.0
        cpe:2.3:a:tibco:jasperreports_server:8.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-04-09 16:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:jasperreports_server:8.0.4:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jasperreports_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0.4"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tibco:jasperreports_server:8.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jasperreports_server",
                "vendor": "tibco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.2.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3323",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-22T21:35:25.685169Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:31:11.990Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.445Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-april-9-2024-tibco-jasperreports-server-cve-2024-3323-r209/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "UI Request/Response Validation"
              ],
              "product": "JasperReports Server",
              "vendor": "TIBCO",
              "versions": [
                {
                  "lessThan": "8.0.4",
                  "status": "affected",
                  "version": "8.0",
                  "versionType": "Hotfix"
                },
                {
                  "lessThan": "8.2.0",
                  "status": "affected",
                  "version": "8.2",
                  "versionType": "Hotfix"
                }
              ]
            }
          ],
          "datePublic": "2024-04-09T16:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross Site Scripting in \n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eUI Request/Response Validation\u003c/span\u003e\n\n in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user\u0027s active session cookie\u0026nbsp;via sending malicious link, enticing the user to interact."
                }
              ],
              "value": "Cross Site Scripting in \n\nUI Request/Response Validation\n\n in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user\u0027s active session cookie\u00a0via sending malicious link, enticing the user to interact."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-17T18:53:21.348Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-april-9-2024-tibco-jasperreports-server-cve-2024-3323-r209/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Reflected Cross Site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-3323",
        "datePublished": "2024-04-17T18:53:21.348Z",
        "dateReserved": "2024-04-04T17:01:23.280Z",
        "dateUpdated": "2024-08-01T20:05:08.445Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1138 (GCVE-0-2024-1138)

    Vulnerability from cvelistv5 – Published: 2024-03-12 17:30 – Updated: 2025-03-28 18:59
    VLAI
    Title
    TIBCO FTL Privilege Escalation
    Summary
    The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 19:05 UTC
    CWE
    • Successful exploitation of this vulnerability may result in an authenticated but unprivileged user arbitrarily reconfiguring FTL clients attached to the same ftlserver.
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. TIBCO FTL - Enterprise Edition Affected: 0 , ≤ 6.10.1 (semver)
    Create a notification for this product.
    tibco ftl Affected: 0 , ≤ 6.10.1 (semver)
        cpe:2.3:a:tibco:ftl:*:*:*:*:enterprise:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:26:30.563Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-12-2024-tibco-ftl-cve-2024-1138-r207/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tibco:ftl:*:*:*:*:enterprise:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "ftl",
                "vendor": "tibco",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1138",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T19:05:22.151041Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-269",
                    "description": "CWE-269 Improper Privilege Management",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-28T18:59:24.770Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "TIBCO FTL - Enterprise Edition",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "6.10.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe FTL Server component of TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.\u003c/p\u003e"
                }
              ],
              "value": "The FTL Server component of TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.\u0027s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Successful exploitation of this vulnerability may result in an authenticated but unprivileged user arbitrarily reconfiguring FTL clients attached to the same ftlserver.",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T17:30:15.100Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://community.tibco.com/advisories/tibco-security-advisory-march-12-2024-tibco-ftl-cve-2024-1138-r207/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO FTL - Enterprise Edition versions 6.10.1 and below: update to version 6.10.2 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO FTL - Enterprise Edition versions 6.10.1 and below: update to version 6.10.2 or later\n\n"
            }
          ],
          "title": "TIBCO FTL Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2024-1138",
        "datePublished": "2024-03-12T17:30:15.100Z",
        "dateReserved": "2024-01-31T20:35:00.843Z",
        "dateUpdated": "2025-03-28T18:59:24.770Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26222 (GCVE-0-2023-26222)

    Vulnerability from cvelistv5 – Published: 2023-11-14 19:29 – Updated: 2024-08-30 14:06
    VLAI
    Title
    TIBCO EBX Cross-site Scripting (XXS) Vulnerability
    Summary
    The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-30 14:06 UTC
    CWE
    • The impact of this vulnerability includes the theoretical possibility resulting in unauthorized ability to update, insert or delete TIBCO EBX® data.
    References
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. TIBCO EBX Affected: 0 , ≤ 5.9.22 (semver)
    Affected: 0 , ≤ 6.0.13 (semver)
    Create a notification for this product.
    TIBCO Software Inc. TIBCO Product and Service Catalog powered by TIBCO EBX Affected: 0 , ≤ 5.0.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.340Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26222",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-30T14:06:41.016491Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-30T14:06:54.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO EBX",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.9.22",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.0.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Product and Service Catalog powered by TIBCO EBX",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Web Application component of TIBCO Software Inc.\u0027s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.\u0027s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.\u003c/p\u003e"
                }
              ],
              "value": "The Web Application component of TIBCO Software Inc.\u0027s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.\u0027s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "The impact of this vulnerability includes the theoretical possibility resulting in unauthorized ability to update, insert or delete TIBCO EBX\u00ae data.",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-11-14T19:29:09.766Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO EBX versions 5.9.22 and below: update to version 5.9.23 or later\u003c/p\u003e\u003cp\u003eTIBCO EBX versions 6.0.13 and below: update to version 6.0.14 or later\u003c/p\u003e\u003cp\u003eTIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below: update to version 5.1.0 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO EBX versions 5.9.22 and below: update to version 5.9.23 or later\n\nTIBCO EBX versions 6.0.13 and below: update to version 6.0.14 or later\n\nTIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below: update to version 5.1.0 or later\n\n"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "TIBCO EBX Cross-site Scripting (XXS) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26222",
        "datePublished": "2023-11-14T19:29:09.766Z",
        "dateReserved": "2023-02-20T22:18:23.428Z",
        "dateUpdated": "2024-08-30T14:06:54.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26221 (GCVE-0-2023-26221)

    Vulnerability from cvelistv5 – Published: 2023-11-08 19:44 – Updated: 2024-09-04 15:46
    VLAI
    Title
    TIBCO Spotfire Insufficiently Protected Credential vulnerability
    Summary
    The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-04 15:46 UTC
    CWE
    • CWE-522 - Insufficiently Protected Credentials
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.940Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26221",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-04T15:46:35.719041Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-04T15:46:47.013Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Analyst",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.3.0"
                },
                {
                  "status": "affected",
                  "version": "12.4.0"
                },
                {
                  "status": "affected",
                  "version": "12.5.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Server",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.3.0"
                },
                {
                  "status": "affected",
                  "version": "12.4.0"
                },
                {
                  "status": "affected",
                  "version": "12.5.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire for AWS Marketplace",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Spotfire Connectors component of TIBCO Software Inc.\u0027s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.\u003c/p\u003e"
                }
              ],
              "value": "The Spotfire Connectors component of TIBCO Software Inc.\u0027s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-522",
                  "description": "CWE-522 Insufficiently Protected Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-11-08T19:44:03.634Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\u003c/p\u003e\u003cp\u003eSpotfire for AWS Marketplace version 12.5.0: update to version 14.0.0 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nSpotfire Analyst versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\n\nSpotfire Server versions 12.3.0, 12.4.0, and 12.5.0: update to version 14.0.0 or later\n\nSpotfire for AWS Marketplace version 12.5.0: update to version 14.0.0 or later\n\n"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "TIBCO Spotfire Insufficiently Protected Credential vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26221",
        "datePublished": "2023-11-08T19:44:03.634Z",
        "dateReserved": "2023-02-20T22:18:23.428Z",
        "dateUpdated": "2024-09-04T15:46:47.013Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26219 (GCVE-0-2023-26219)

    Vulnerability from cvelistv5 – Published: 2023-10-24 21:56 – Updated: 2024-09-11 17:07
    VLAI
    Title
    TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability
    Summary
    The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-11 17:07 UTC
    CWE
    • The impact of this vulnerability includes the theoretical possibility that an attacker could access the message stream of the EMS server, or in the worst case, gain administrative access to the server.
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.339Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26219",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-11T17:07:16.001862Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-11T17:07:46.968Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Hawk",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "6.2.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Hawk Distribution for TIBCO Silver Fabric",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "6.2.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Operational Intelligence Hawk RedTail",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Runtime Agent",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.12.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Hawk Console and Hawk Agent components of TIBCO Software Inc.\u0027s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console\u2019s and Agent\u2019s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.\u0027s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.\u003c/p\u003e"
                }
              ],
              "value": "The Hawk Console and Hawk Agent components of TIBCO Software Inc.\u0027s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console\u2019s and Agent\u2019s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.\u0027s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, and TIBCO Runtime Agent: versions 5.12.2 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "The impact of this vulnerability includes the theoretical possibility that an attacker could access the message stream of the EMS server, or in the worst case, gain administrative access to the server.",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-24T21:56:50.294Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO Hawk versions 6.2.2 and below: update to version 6.2.3 or later\u003c/p\u003e\u003cp\u003eTIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below: update to version 6.2.3 or later\u003c/p\u003e\u003cp\u003eTIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below: update to version 7.2.2 or later\u003c/p\u003e\u003cp\u003eTIBCO Runtime Agent versions 5.12.2 and below: update to version 5.12.3 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO Hawk versions 6.2.2 and below: update to version 6.2.3 or later\n\nTIBCO Hawk Distribution for TIBCO Silver Fabric versions 6.2.2 and below: update to version 6.2.3 or later\n\nTIBCO Operational Intelligence Hawk RedTail versions 7.2.1 and below: update to version 7.2.2 or later\n\nTIBCO Runtime Agent versions 5.12.2 and below: update to version 5.12.3 or later\n\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIBCO Operational Intelligence Hawk RedTail Credential Exposure Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26219",
        "datePublished": "2023-10-24T21:56:50.294Z",
        "dateReserved": "2023-02-20T22:18:23.427Z",
        "dateUpdated": "2024-09-11T17:07:46.968Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26220 (GCVE-0-2023-26220)

    Vulnerability from cvelistv5 – Published: 2023-10-10 22:06 – Updated: 2024-09-18 16:14
    VLAI
    Title
    TIBCO Spotfire Stored Cross-site Scripting (XSS) vulnerability
    Summary
    The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 16:14 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. Spotfire Analyst Affected: 0 , ≤ 11.4.7 (semver)
    Affected: 11.5.0
    Affected: 11.6.0
    Affected: 11.7.0
    Affected: 11.8.0
    Affected: 12.0.0
    Affected: 12.0.1
    Affected: 12.0.2
    Affected: 12.0.3
    Affected: 12.0.4
    Affected: 12.1.0
    Affected: 12.1.1
    Create a notification for this product.
    TIBCO Software Inc. Spotfire Server Affected: 0 , ≤ 11.4.11 (semver)
    Affected: 11.5.0
    Affected: 11.6.0
    Affected: 11.6.1
    Affected: 11.6.2
    Affected: 11.6.3
    Affected: 11.7.0
    Affected: 11.8.0
    Affected: 11.8.1
    Affected: 12.0.0
    Affected: 12.0.1
    Affected: 12.0.2
    Affected: 12.0.3
    Affected: 12.0.4
    Affected: 12.0.5
    Affected: 12.1.0
    Affected: 12.1.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:24.112Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26220",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T16:14:40.488828Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T16:14:49.914Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Analyst",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "11.4.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "affected",
                  "version": "11.5.0"
                },
                {
                  "status": "affected",
                  "version": "11.6.0"
                },
                {
                  "status": "affected",
                  "version": "11.7.0"
                },
                {
                  "status": "affected",
                  "version": "11.8.0"
                },
                {
                  "status": "affected",
                  "version": "12.0.0"
                },
                {
                  "status": "affected",
                  "version": "12.0.1"
                },
                {
                  "status": "affected",
                  "version": "12.0.2"
                },
                {
                  "status": "affected",
                  "version": "12.0.3"
                },
                {
                  "status": "affected",
                  "version": "12.0.4"
                },
                {
                  "status": "affected",
                  "version": "12.1.0"
                },
                {
                  "status": "affected",
                  "version": "12.1.1"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Spotfire Server",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "11.4.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "affected",
                  "version": "11.5.0"
                },
                {
                  "status": "affected",
                  "version": "11.6.0"
                },
                {
                  "status": "affected",
                  "version": "11.6.1"
                },
                {
                  "status": "affected",
                  "version": "11.6.2"
                },
                {
                  "status": "affected",
                  "version": "11.6.3"
                },
                {
                  "status": "affected",
                  "version": "11.7.0"
                },
                {
                  "status": "affected",
                  "version": "11.8.0"
                },
                {
                  "status": "affected",
                  "version": "11.8.1"
                },
                {
                  "status": "affected",
                  "version": "12.0.0"
                },
                {
                  "status": "affected",
                  "version": "12.0.1"
                },
                {
                  "status": "affected",
                  "version": "12.0.2"
                },
                {
                  "status": "affected",
                  "version": "12.0.3"
                },
                {
                  "status": "affected",
                  "version": "12.0.4"
                },
                {
                  "status": "affected",
                  "version": "12.0.5"
                },
                {
                  "status": "affected",
                  "version": "12.1.0"
                },
                {
                  "status": "affected",
                  "version": "12.1.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Spotfire Library component of TIBCO Software Inc.\u0027s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.\u003c/p\u003e"
                }
              ],
              "value": "The Spotfire Library component of TIBCO Software Inc.\u0027s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-10T22:06:36.002Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 11.4.7 and below: update to version 11.4.8 or later\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4: update to version 12.0.5 or later\u003c/p\u003e\u003cp\u003eSpotfire Analyst versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 11.4.11 and below: update to version 11.4.12 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5: update to version 12.0.6 or later\u003c/p\u003e\u003cp\u003eSpotfire Server versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nSpotfire Analyst versions 11.4.7 and below: update to version 11.4.8 or later\n\nSpotfire Analyst versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4: update to version 12.0.5 or later\n\nSpotfire Analyst versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\n\nSpotfire Server versions 11.4.11 and below: update to version 11.4.12 or later\n\nSpotfire Server versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5: update to version 12.0.6 or later\n\nSpotfire Server versions 12.1.0 and 12.1.1: update to version 12.5.0 or later\n\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIBCO Spotfire Stored Cross-site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26220",
        "datePublished": "2023-10-10T22:06:36.002Z",
        "dateReserved": "2023-02-20T22:18:23.427Z",
        "dateUpdated": "2024-09-18T16:14:49.914Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26218 (GCVE-0-2023-26218)

    Vulnerability from cvelistv5 – Published: 2023-09-29 17:07 – Updated: 2024-09-23 16:26
    VLAI
    Title
    TIBCO Nimbus Reflected Cross-site Scripting (XSS) vulnerabilities
    Summary
    The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.6.0 and below.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-23 16:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    TIBCO Software Inc. TIBCO Nimbus Affected: 0 , ≤ 10.6.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.316Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tibco.com/services/support/advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26218",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-23T16:26:16.962584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-23T16:26:35.804Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TIBCO Nimbus",
              "vendor": "TIBCO Software Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "10.6.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Web Client component of TIBCO Software Inc.\u0027s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim\u0027s local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s TIBCO Nimbus: versions 10.6.0 and below.\u003c/p\u003e"
                }
              ],
              "value": "The Web Client component of TIBCO Software Inc.\u0027s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim\u0027s local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\u0027s TIBCO Nimbus: versions 10.6.0 and below.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-29T17:07:11.618Z",
            "orgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
            "shortName": "tibco"
          },
          "references": [
            {
              "url": "https://www.tibco.com/services/support/advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTIBCO has released updated versions of the affected components which address these issues.\u003c/p\u003e\u003cp\u003eTIBCO Nimbus versions 10.6.0 and below: update to version 10.6.1 or later\u003c/p\u003e"
                }
              ],
              "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO Nimbus versions 10.6.0 and below: update to version 10.6.1 or later\n\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIBCO Nimbus Reflected Cross-site Scripting (XSS) vulnerabilities",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4f830c72-39e4-45f6-a99f-78cc01ae04db",
        "assignerShortName": "tibco",
        "cveId": "CVE-2023-26218",
        "datePublished": "2023-09-29T17:07:11.618Z",
        "dateReserved": "2023-02-20T22:18:23.427Z",
        "dateUpdated": "2024-09-23T16:26:35.804Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }