CVE-2015-4554: High severity tibco spotfire deployment kit vulnerability
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Deployment Kit before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Desktop before 6.5.2 and 7.0.x before 7.0.1; Spotfire Desktop Language Packs 7.0.x before 7.0.1; Spotfire Professional before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Web Player before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; and Silver Fabric Enabler for Spotfire Web Player before 2.1.1 allow remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4554?
CVE-2015-4554 has a high severity rating due to multiple unspecified vulnerabilities in TIBCO Spotfire products.
How do I fix CVE-2015-4554?
To fix CVE-2015-4554, upgrade TIBCO Spotfire to the latest versions: 5.5.2, 6.0.3, 6.5.3, or 7.0.1.
Which TIBCO Spotfire versions are affected by CVE-2015-4554?
CVE-2015-4554 affects TIBCO Spotfire client versions before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1.
Are both TIBCO Spotfire Client and Web Player affected by CVE-2015-4554?
Yes, both TIBCO Spotfire Client and Spotfire Web Player Client are affected by CVE-2015-4554.
What types of systems are impacted by CVE-2015-4554?
CVE-2015-4554 impacts TIBCO Spotfire Analyst, Professional, Web Player, Automation Services, and the Analytics Platform for AWS.