CVE-2019-11204: TIBCO Spotfire Statistics Services Exposes Sensitive Files
The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-11204?
CVE-2019-11204 is a vulnerability in TIBCO Spotfire Statistics Services that allows an authenticated user to access sensitive information.
What is the severity of CVE-2019-11204?
CVE-2019-11204 has a severity rating of critical (8.8).
How does CVE-2019-11204 affect TIBCO Spotfire Statistics Services?
CVE-2019-11204 affects TIBCO Spotfire Statistics Services versions 7.11.1 and 10.0.0.
How can an authenticated user exploit the vulnerability in CVE-2019-11204?
An authenticated user can exploit the vulnerability in CVE-2019-11204 to potentially access sensitive information needed by the Spotfire Statistics Services server.
Is there a patch available to fix CVE-2019-11204?
Yes, TIBCO Software Inc. has released patches to address the vulnerability in CVE-2019-11204. It is recommended to update to the latest version of TIBCO Spotfire Statistics Services.