First published: Fri Sep 02 2011(Updated: )
Unspecified vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire Analytics Server | <=10.0.1 | |
TIBCO Spotfire Analytics Server | =10.0.0 | |
TIBCO Spotfire | =3.0.0 | |
TIBCO Spotfire | =3.0.1 | |
TIBCO Spotfire | =3.1.0 | |
TIBCO Spotfire | =3.1.1 | |
TIBCO Spotfire | =3.2.0 | |
TIBCO Spotfire | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3134 is categorized as high due to its potential for remote data modification and information disclosure.
CVE-2011-3134 affects TIBCO Spotfire Server versions 3.0.x through 3.3.x and Spotfire Analytics Server versions prior to 10.1.1.
To fix CVE-2011-3134, upgrade to TIBCO Spotfire Server 3.0.2, 3.1.2, 3.2.1, 3.3.1, or any version of Spotfire Analytics Server 10.1.1 or later.
The risks associated with CVE-2011-3134 include unauthorized modification of data and potential exposure of sensitive information through crafted URLs.
Yes, CVE-2011-3134 can be exploited remotely by attackers leveraging specially crafted URLs.