CVE-2023-26220: TIBCO Spotfire Stored Cross-site Scripting (XSS) vulnerability
The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-26220.
What is the severity level of CVE-2023-26220?
The severity level of CVE-2023-26220 is medium (5.4).
What software components are affected by CVE-2023-26220?
TIBCO Spotfire Analyst and TIBCO Spotfire Server are affected by CVE-2023-26220.
How can an attacker exploit CVE-2023-26220?
An attacker with network access can exploit CVE-2023-26220 to execute a Stored Cross Site Scripting (XSS) attack on the affected system.
Where can I find more information about CVE-2023-26220?
You can find more information about CVE-2023-26220 on the TIBCO Software Inc. advisory page.