CVE-2018-18813

HIGH

TIBCO Spotfire Analytics Platform for AWS < 10.0.0 and Spotfire Server <= 7.10.1 - XSS

Title source: llm
STIX 2.1

Description

The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.0.0, and TIBCO Spotfire Server: versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0; 10.0.0.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106635
Vendor Advisory x_refsource_misc
http://www.tibco.com/services/support/advisories

Scores

CVSS v3 8.8
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (8)
tibco/spotfire_analytics_platform_for_aws < 10.0.0
tibco/spotfire_server 7.11.0
tibco/spotfire_server 7.11.1
tibco/spotfire_server 7.12.0
tibco/spotfire_server 7.13.0
tibco/spotfire_server 7.14.0
tibco/spotfire_server 10.0.0
tibco/spotfire_server < 7.10.1
Published Jan 16, 2019
Tracked Since Feb 18, 2026