First published: Tue Sep 20 2022(Updated: )
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tibco Spotfire Analytics Platform | =12.0.0 | |
TIBCO Spotfire Server | =12.0.0 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Spotfire Analytics Platform for AWS Marketplace version 12.0.0: update to version 12.0.1 or later TIBCO Spotfire Server version 12.0.0: update to version 12.0.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this TIBCO Spotfire Analytics Platform and Spotfire Server vulnerability is CVE-2022-30579.
CVE-2022-30579 has a severity rating of 8.4, which is considered high.
The affected software for CVE-2022-30579 is TIBCO Spotfire Analytics Platform version 12.0.0 for AWS Marketplace and TIBCO Spotfire Server version 12.0.0.
CVE-2022-30579 is a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected TIBCO Spotfire Analytics Platform and Spotfire Server.
You can find more information about CVE-2022-30579 in the TIBCO Security Advisories at https://www.tibco.com/services/support/advisories and specifically at https://www.tibco.com/support/advisories/2022/09/tibco-security-advisory-september-20-2022-tibco-spotfire-cve-2022-30579.