CVE-2018-18813
HIGHTIBCO Spotfire Analytics Platform for AWS < 10.0.0 and Spotfire Server <= 7.10.1 - XSS
Title source: llmDescription
The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.0.0, and TIBCO Spotfire Server: versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0; 10.0.0.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106635
Vendor Advisory x_refsource_misc
http://www.tibco.com/services/support/advisories
Vendor Advisory x_refsource_confirm
https://www.tibco.com/support/advisories/2019/01/tibco-security-advisory-january-16-2019-tibco-spotfire-2018-18813
Scores
CVSS v3
8.8
EPSS
0.0027
EPSS Percentile
50.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-79
Status
published
Products (8)
tibco/spotfire_analytics_platform_for_aws
< 10.0.0
tibco/spotfire_server
7.11.0
tibco/spotfire_server
7.11.1
tibco/spotfire_server
7.12.0
tibco/spotfire_server
7.13.0
tibco/spotfire_server
7.14.0
tibco/spotfire_server
10.0.0
tibco/spotfire_server
< 7.10.1
Published
Jan 16, 2019
Tracked Since
Feb 18, 2026