CVE-2018-18812
MEDIUMTibco Spotfire Analytics Platform For... - Incorrect Permission Assignment
Title source: ruleDescription
The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability that might theoretically fail to restrict users with read-only access from modifying files stored in the Spotfire Library, only when the Spotfire Library is configured to use external storage. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace versions up to and including 10.0.0, and TIBCO Spotfire Server versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0; 10.0.0.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106635
Vendor Advisory x_refsource_confirm
https://www.tibco.com/support/advisories/2019/01/tibco-security-advisory-january-16-2019-tibco-spotfire-2018-18812
Vendor Advisory x_refsource_misc
http://www.tibco.com/services/support/advisories
Scores
CVSS v3
6.5
EPSS
0.0014
EPSS Percentile
33.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-732
Status
published
Products (8)
tibco/spotfire_analytics_platform_for_aws
< 10.0.0
tibco/spotfire_server
7.11.0
tibco/spotfire_server
7.11.1
tibco/spotfire_server
7.12.0
tibco/spotfire_server
7.13.0
tibco/spotfire_server
7.14.0
tibco/spotfire_server
10.0.0
tibco/spotfire_server
< 7.10.1
Published
Jan 16, 2019
Tracked Since
Feb 18, 2026