Back to overview

CVE-2019-11204

CRITICAL
9.9
CVSS 3.0
Description
The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.

Metadata

CVE ID
CVE-2019-11204
State
PUBLISHED
Assigner
tibco
Reserved
2019-04-12 00:00 UTC
Published
2019-05-14 19:57 UTC
Last updated
2024-09-16 17:53 UTC
Vendor / Product
TIBCO Software Inc. / TIBCO Spotfire Statistics Services
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
TIBCO Software Inc. TIBCO Spotfire Statistics Services unspecified ≤ 7.11.1, 10.0.0
Weakness (CWE)
CWESourceDescription
cna The impact of this vulnerability includes the theoretical possibility that credentials to both the Spotfire Statistics Services server, and to other systems could be exposed.
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview