The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.10.2, versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 11.1.0 and below, TIBCO Spotfire Desktop: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.10.2, versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0, and TIBCO Spotfire Server: versions 10.3.11 and below, versions 10.10.0, 10.10.1, 10.10.2, and 10.10.3, versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 11.0.0, and 11.1.0.
References
Link | Resource |
---|---|
http://www.tibco.com/services/support/advisories | Vendor Advisory |
https://www.tibco.com/support/advisories/2021/03/tibco-security-advisory-march-9-2021-tibco-spotfire | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Mar 2021, 20:42
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:tibco:spotfire_server:10.10.3:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.10.2:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:10.10.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:10.8.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:10.10.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:analytics_platform:*:*:*:*:*:aws_marketplace:*:* cpe:2.3:a:tibco:spotfire_analyst:10.9.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:10.9.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:10.10.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.8.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.9.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:10.7.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:10.7.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.10.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:10.10.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.8.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:10.10.2:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.10.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:10.8.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_server:10.7.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:10.10.2:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.4 |
CWE | CWE-79 | |
References | (CONFIRM) http://www.tibco.com/services/support/advisories - Vendor Advisory | |
References | (CONFIRM) https://www.tibco.com/support/advisories/2021/03/tibco-security-advisory-march-9-2021-tibco-spotfire - Vendor Advisory |
09 Mar 2021, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-03-09 21:15
Updated : 2023-12-10 13:41
NVD link : CVE-2021-23273
Mitre link : CVE-2021-23273
CVE.ORG link : CVE-2021-23273
JSON object : View
Products Affected
tibco
- spotfire_desktop
- spotfire_analyst
- spotfire_server
- analytics_platform
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')