First published: Fri Mar 15 2013(Updated: )
The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire Statistics Services | =3.3 | |
TIBCO Spotfire Statistics Services | =4.5.0 | |
TIBCO Spotfire Statistics Services | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2371 is classified as a medium severity vulnerability due to its potential impact on sensitive information exposure.
To fix CVE-2013-2371, upgrade TIBCO Spotfire Statistics Services to version 3.3.1, 4.5.1, or 5.0.1 or later.
CVE-2013-2371 can be exploited by remote attackers to gain unauthorized access to sensitive information through crafted HTTP requests.
CVE-2013-2371 affects TIBCO Spotfire Statistics Services versions 3.3, 4.5.0, and 5.0.0.
There are no specific workarounds recommended for CVE-2013-2371, so the best practice is to upgrade to a patched version.