CVE-2014-7195: Infoleak
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7195?
CVE-2014-7195 is classified as a medium severity vulnerability due to its potential impact on sensitive information leakage.
How do I fix CVE-2014-7195?
To fix CVE-2014-7195, upgrade TIBCO Spotfire Web Player to version 6.0.2 or 6.5.2, or the Silver Fabric Enabler to version 1.6.1 or later.
Which versions are affected by CVE-2014-7195?
CVE-2014-7195 affects TIBCO Spotfire Web Player versions 6.0.0-6.0.1 and 6.5.0-6.5.1, as well as TIBCO Spotfire Deployment Kit versions 6.0.0-6.0.1 and 6.5.0-6.5.1.
Who is at risk from CVE-2014-7195?
Remote authenticated users of affected TIBCO Spotfire Web Player installations are at risk from CVE-2014-7195.
What type of vulnerability is CVE-2014-7195?
CVE-2014-7195 is an information disclosure vulnerability allowing unauthorized access to sensitive information.