CVE-2019-17337: TIBCO Spotfire Server Library Vulnerable to Reflected Cross-Site Scripting
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflected cross-site scripting (XSS) attack. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0 and TIBCO Spotfire Server: versions 7.11.7 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.3.2, 10.3.3, and 10.3.4, versions 10.4.0, 10.5.0, and 10.6.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-17337.
What is the severity of CVE-2019-17337?
The severity of CVE-2019-17337 is high with a CVSS score of 5.4.
Which software products are affected by CVE-2019-17337?
TIBCO Spotfire Analytics Platform for AWS (version 10.6.0) and TIBCO Spotfire Server (versions 7.11.7 to 10.6.0) are affected by CVE-2019-17337.
What is the nature of the vulnerability?
The vulnerability allows an attacker to perform a reflected cross-site scripting (XSS) attack.
Where can I find more information about CVE-2019-17337?
For more information about CVE-2019-17337, you can visit the TIBCO security advisories page or the TIBCO support advisories page.