First published: Tue May 14 2019(Updated: )
The web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: 7.14.0; 7.14.1; 10.0.0; 10.0.1; 10.1.0; 10.2.0, and TIBCO Spotfire Server: 7.14.0; 10.0.0; 10.0.1; 10.1.0; 10.2.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire Analytics Platform for AWS | =7.14.0 | |
TIBCO Spotfire Analytics Platform for AWS | =7.14.1 | |
TIBCO Spotfire Analytics Platform for AWS | =10.0.0 | |
TIBCO Spotfire Analytics Platform for AWS | =10.0.1 | |
TIBCO Spotfire Analytics Platform for AWS | =10.1.0 | |
TIBCO Spotfire Analytics Platform for AWS | =10.2.0 | |
TIBCO Spotfire Server | =7.14.0 | |
TIBCO Spotfire Server | =10.0.0 | |
TIBCO Spotfire Server | =10.0.1 | |
TIBCO Spotfire Server | =10.1.0 | |
TIBCO Spotfire Server | =10.2.0 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Spotfire Analytics Platform for AWS Marketplace versions 7.14.0, 7.14.1, 10.0.0, 10.0.1, 10.1.0, and 10.2.0 update to 10.3.0 or higher TIBCO Spotfire Server versions 7.14.0, 10.0.0, 10.0.1, 10.1.0, and 10.2.0 update to 10.2.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11205 is a vulnerability in the web server component of TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server that allows for reflected cross-site scripting (XSS) attacks.
Versions 7.14.0, 7.14.1, 10.0.0, 10.0.1, 10.1.0, and 10.2.0 of TIBCO Spotfire Analytics Platform for AWS Marketplace are affected by CVE-2019-11205.
Versions 7.14.0, 10.0.0, 10.0.1, 10.1.0, and 10.2.0 of TIBCO Spotfire Server are affected by CVE-2019-11205.
CVE-2019-11205 has a severity rating of 6.1 (high).
To fix CVE-2019-11205, users should apply the necessary security updates provided by TIBCO Software Inc and follow the recommendations outlined in their security advisory.