CVE-2018-18812

MEDIUM

Tibco Spotfire Analytics Platform For... - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability that might theoretically fail to restrict users with read-only access from modifying files stored in the Spotfire Library, only when the Spotfire Library is configured to use external storage. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace versions up to and including 10.0.0, and TIBCO Spotfire Server versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0; 10.0.0.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106635
Vendor Advisory x_refsource_misc
http://www.tibco.com/services/support/advisories

Scores

CVSS v3 6.5
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-732
Status published
Products (8)
tibco/spotfire_analytics_platform_for_aws < 10.0.0
tibco/spotfire_server 7.11.0
tibco/spotfire_server 7.11.1
tibco/spotfire_server 7.12.0
tibco/spotfire_server 7.13.0
tibco/spotfire_server 7.14.0
tibco/spotfire_server 10.0.0
tibco/spotfire_server < 7.10.1
Published Jan 16, 2019
Tracked Since Feb 18, 2026