tibco
229 tracked vulnerabilities.
CVE-2022-41558
CRITICAL
TIBCO Spotfire Analyst < 11.4.4, 11.5.0-12.0.1, 12.1.0 - Stored Cross-Site Scripting in Visualizations Component
Nov 15, 2022
CVSS 9.0
EPSS 0.01
CVE-2022-30578
HIGH
TIBCO EBX Add-ons < 5.4.2 - Stored Cross-Site Scripting
Sep 21, 2022
CVSS 8.0
EPSS 0.01
CVE-2022-30577
HIGH
TIBCO EBX 6.0.0-6.0.8 - Stored Cross-Site Scripting
Sep 21, 2022
CVSS 8.0
EPSS 0.01
CVE-2022-30579
HIGH
TIBCO Spotfire Analytics Platform and Spotfire Server 12.0.0 - Server-Side Request Forgery in Web Player
Sep 20, 2022
CVSS 7.1
EPSS 0.00
CVE-2022-30576
HIGH
TIBCO Data Science - Workbench and Statistica < 14.0.1 - Stored Cross-Site Scripting in Web Console
Aug 16, 2022
CVSS 8.7
EPSS 0.01
CVE-2022-30575
HIGH
TIBCO Data Science - Workbench and Statistica < 14.0.1 - Reflected Cross-Site Scripting
Aug 16, 2022
CVSS 7.3
EPSS 0.01
CVE-2022-30574
MEDIUM
TIBCO FTL and eFTL 6.0.0-6.8.0 - Credential Exposure via ftlserver Component
Aug 09, 2022
CVSS 4.6
EPSS 0.00
CVE-2022-30573
MEDIUM
TIBCO FTL 6.0.0-6.8.0 - Privilege Escalation in ftlserver Component
Aug 09, 2022
CVSS 6.7
EPSS 0.01
CVE-2022-30572
MEDIUM
TIBCO iWay Service Manager < 8.0.7 - Path Traversal in Console Component
Aug 02, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-30571
HIGH
TIBCO iWay Service Manager < 8.0.7 - Reflected Cross-Site Scripting in Console Component
Aug 02, 2022
CVSS 8.1
EPSS 0.01
CVE-2022-30570
MEDIUM
TIBCO Data Virtualization <8.5.2 - Info Disclosure
Jul 19, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-22778
HIGH
TIBCO BusinessConnect Trading Community Management < 6.1.1 - Unauthenticated Cross-Site Request Forgery
May 18, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-22777
MEDIUM
TIBCO BusinessConnect Trading Community Management < 6.1.1 - Unauthenticated Reflected Cross-Site Scripting
May 18, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-22776
HIGH
TIBCO BusinessConnect Trading Community Management < 6.1.1 - Stored Cross-Site Scripting
May 18, 2022
CVSS 8.0
EPSS 0.01
CVE-2022-22775
HIGH
TIBCO BPM Enterprise < 4.3.2 - Reflected Cross-Site Scripting in Workspace Client
May 17, 2022
CVSS 8.1
EPSS 0.01
CVE-2022-22773
HIGH
TIBCO JasperReports Server < 7.9.2, < 8.0.2 - Reflected Cross-Site Scripting in REST API
May 17, 2022
CVSS 7.7
EPSS 0.01
CVE-2022-22774
HIGH
TIBCO Managed File Transfer Command Center and Internet Server < 8.3.2 - Unauthenticated XML External Entity Injection
May 10, 2022
CVSS 8.6
EPSS 0.01
CVE-2022-22772
HIGH
TIBCO Managed File Transfer Platform Server < 8.1.1 - Remote Code Execution in cfsend, cfrecv, and CyberResp Components
Mar 30, 2022
CVSS 8.5
EPSS 0.01
CVE-2022-22771
HIGH
TIBCO JasperReports Library and Server 7.9.0-7.9.1 - Path Traversal
Mar 15, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-22770
CRITICAL
TIBCO AuditSafe < 1.1.1 - Unauthenticated API Method Execution
Feb 15, 2022
CVSS 9.8
EPSS 0.02
CVE-2022-22769
HIGH
TIBCO EBX < 5.8.125 and Add-ons < 3.20.19 - Stored Cross-Site Scripting
Jan 19, 2022
CVSS 8.0
EPSS 0.00
CVE-2021-43050
HIGH
TIBCO BusinessConnect Container Edition <1.1.0 - Info Disclosure
Feb 15, 2022
CVSS 8.4
EPSS 0.00
CVE-2021-43049
CRITICAL
TIBCO BusinessConnect Container Edition <1.1.0 - Info Disclosure
Feb 15, 2022
CVSS 9.8
EPSS 0.00
CVE-2021-35500
MEDIUM
TIBCO Data Virtualization <8.3.0 - Info Disclosure
Jan 12, 2022
CVSS 6.3
EPSS 0.00
CVE-2021-43055
MEDIUM
TIBCO eFTL <6.7.2 - Privilege Escalation
Jan 11, 2022
CVSS 5.9
EPSS 0.00
Products
spotfire_server 28
jasperreports_server 22
spotfire_analytics_platform_for_aws 20
rendezvous 16
spotfire_analyst 12
enterprise_message_service 11
jaspersoft 10
jaspersoft_reporting_and_analytics 10
managed_file_transfer_command_center 10
managed_file_transfer_internet_server 10
spotfire_desktop 10
ebx 9
ebx_add-ons 9
ftl 9
runtime_agent 9
activematrix_bpm 8
activematrix_service_bus 8
activematrix_service_grid 8
spotfire_deployment_kit 8
silver_fabric_enabler 7
spotfire_analytics_platform 7
spotfire_statistics_services 7
administrator 6
hawk 6
spotfire_desktop_language_packs 6
activematrix_businessworks_service_engine 5
eftl 5
iprocess_engine 5
jasperreports_library 5
rtworks 5
Quick Filters