CVE-2018-18814: TIBCO Spotfire Authentication Vulnerability
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker to gain full access to a target account, independent of configured authentication mechanisms. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.0.0, and TIBCO Spotfire Server: versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2018-18814?
CVE-2018-18814 is a vulnerability in the TIBCO Spotfire authentication component.
What software is affected by CVE-2018-18814?
The TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server versions up to 10.0.0 are affected.
What is the severity of CVE-2018-18814?
CVE-2018-18814 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2018-18814?
An attacker can theoretically gain full access to a target account through the vulnerability in the authentication component.
Are there any fixes or patches available for CVE-2018-18814?
Please refer to the TIBCO Security Advisory for information on fixes and patches for CVE-2018-18814.