CVE-2022-30579

HIGH

TIBCO Spotfire Analytics Platform and Spotfire Server 12.0.0 - Server-Side Request Forgery in Web Player

Title source: llm
STIX 2.1

Description

The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.

References (2)

Core 2

Scores

CVSS v3 7.1
EPSS 0.0025
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
tibco/spotfire_analytics_platform 12.0.0
tibco/spotfire_server 12.0.0
Published Sep 20, 2022
Tracked Since Feb 18, 2026