CVE-2013-2371: Infoleak
The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2371?
CVE-2013-2371 is classified as a medium severity vulnerability due to its potential impact on sensitive information exposure.
How do I fix CVE-2013-2371?
To fix CVE-2013-2371, upgrade TIBCO Spotfire Statistics Services to version 3.3.1, 4.5.1, or 5.0.1 or later.
What types of attacks are possible with CVE-2013-2371?
CVE-2013-2371 can be exploited by remote attackers to gain unauthorized access to sensitive information through crafted HTTP requests.
Which versions of TIBCO Spotfire Statistics Services are affected by CVE-2013-2371?
CVE-2013-2371 affects TIBCO Spotfire Statistics Services versions 3.3, 4.5.0, and 5.0.0.
Is there a workaround for CVE-2013-2371 if I cannot upgrade?
There are no specific workarounds recommended for CVE-2013-2371, so the best practice is to upgrade to a patched version.