First published: Tue Jul 21 2015(Updated: )
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Deployment Kit before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Desktop before 6.5.2 and 7.0.x before 7.0.1; Spotfire Desktop Language Packs 7.0.x before 7.0.1; Spotfire Professional before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Web Player before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; and Silver Fabric Enabler for Spotfire Web Player before 2.1.1 allow remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire Deployment Kit | <=5.5.1 | |
TIBCO Spotfire Deployment Kit | =6.0.0 | |
TIBCO Spotfire Deployment Kit | =6.0.1 | |
TIBCO Spotfire Deployment Kit | =6.0.2 | |
TIBCO Spotfire Deployment Kit | =6.5.0 | |
TIBCO Spotfire Deployment Kit | =6.5.1 | |
TIBCO Spotfire Deployment Kit | =6.5.2 | |
TIBCO Spotfire Deployment Kit | =7.0.0 | |
TIBCO Spotfire Professional | <=5.5.1 | |
TIBCO Spotfire Professional | =6.0.0 | |
TIBCO Spotfire Professional | =6.0.1 | |
TIBCO Spotfire Professional | =6.0.2 | |
TIBCO Spotfire Professional | =6.5.0 | |
TIBCO Spotfire Professional | =6.5.1 | |
TIBCO Spotfire Professional | =6.5.2 | |
TIBCO Spotfire Professional | =7.0.0 | |
TIBCO Spotfire Web Player | <=5.5.1 | |
TIBCO Spotfire Web Player | =6.0.0 | |
TIBCO Spotfire Web Player | =6.0.1 | |
TIBCO Spotfire Web Player | =6.0.2 | |
TIBCO Spotfire Web Player | =6.5.0 | |
TIBCO Spotfire Web Player | =6.5.1 | |
TIBCO Spotfire Web Player | =6.5.2 | |
TIBCO Spotfire Web Player | =7.0.0 | |
TIBCO Spotfire Desktop | <=6.5.1 | |
TIBCO Spotfire Desktop | =7.0.0 | |
TIBCO Spotfire Desktop Language Packs | =7.0.0 | |
TIBCO Spotfire Automation Services | <=5.5.1 | |
TIBCO Spotfire Automation Services | =6.0.0 | |
TIBCO Spotfire Automation Services | =6.0.1 | |
TIBCO Spotfire Automation Services | =6.0.2 | |
TIBCO Spotfire Automation Services | =6.5.0 | |
TIBCO Spotfire Automation Services | =6.5.1 | |
TIBCO Spotfire Automation Services | =6.5.2 | |
TIBCO Spotfire Automation Services | =7.0.0 | |
TIBCO Spotfire Analyst | <=5.5.1 | |
TIBCO Spotfire Analyst | =6.0.0 | |
TIBCO Spotfire Analyst | =6.0.1 | |
TIBCO Spotfire Analyst | =6.0.2 | |
TIBCO Spotfire Analyst | =6.5.0 | |
TIBCO Spotfire Analyst | =6.5.1 | |
TIBCO Spotfire Analyst | =6.5.2 | |
TIBCO Spotfire Analyst | =7.0.0 | |
Tibco Silver Fabric Enabler For Spotfire Webplayer | =2.1.0 | |
TIBCO Spotfire Analytics Platform for AWS | =6.5 | |
TIBCO Spotfire Analytics Platform for AWS | =7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4554 has a high severity rating due to multiple unspecified vulnerabilities in TIBCO Spotfire products.
To fix CVE-2015-4554, upgrade TIBCO Spotfire to the latest versions: 5.5.2, 6.0.3, 6.5.3, or 7.0.1.
CVE-2015-4554 affects TIBCO Spotfire client versions before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1.
Yes, both TIBCO Spotfire Client and Spotfire Web Player Client are affected by CVE-2015-4554.
CVE-2015-4554 impacts TIBCO Spotfire Analyst, Professional, Web Player, Automation Services, and the Analytics Platform for AWS.