CVE-2014-2544

TIBCO Spotfire <3.3.4, <4.5.1, <5.0.2, <5.5.1, <6.0.2 - Unspecified...

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Automation Services 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Deployment Kit 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Desktop 6.x before 6.0.1; and Spotfire Analyst 6.x before 6.0.1 allows remote attackers to execute arbitrary code via unknown vectors.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.tibco.com/mk/advisory.jsp

Scores

EPSS 0.0118
EPSS Percentile 79.0%

Details

Status published
Products (37)
tibco/analyst < 6.0.0
tibco/automation_services 4.5.0
tibco/automation_services 4.5.1
tibco/automation_services 5.0.0
tibco/automation_services 5.0.1
tibco/automation_services 5.5.0
tibco/automation_services 6.0.0
tibco/automation_services < 4.0.3
tibco/deployment_kit 4.5.0
tibco/deployment_kit 4.5.1
... and 27 more
Published Apr 10, 2014
Tracked Since Feb 18, 2026