CVE-2019-17337

MEDIUM

TIBCO Spotfire Server < 7.11.7 and 7.12.0-10.6.0 - Reflected Cross-Site Scripting

Title source: llm
STIX 2.1

Description

The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflected cross-site scripting (XSS) attack. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0 and TIBCO Spotfire Server: versions 7.11.7 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.3.2, 10.3.3, and 10.3.4, versions 10.4.0, 10.5.0, and 10.6.0.

Scores

CVSS v3 5.4
EPSS 0.0032
EPSS Percentile 55.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (18)
tibco/spotfire_analytics_platform_for_aws 10.6.0
tibco/spotfire_server 7.12.0
tibco/spotfire_server 7.13.0
tibco/spotfire_server 7.14.0
tibco/spotfire_server 10.0.0
tibco/spotfire_server 10.0.1
tibco/spotfire_server 10.1.0
tibco/spotfire_server 10.2.0
tibco/spotfire_server 10.2.1
tibco/spotfire_server 10.3.0
... and 8 more
Published Dec 17, 2019
Tracked Since Feb 18, 2026