Product:

Spotfire_professional

(Tibco)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 4
Date Id Summary Products Score Patch Annotated
2018-07-24 CVE-2017-3180 Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks. The products and versions that are affected include the following: TIBCO Silver Fabric... Silver_fabric_enabler_for_spotfire_web_player, Spotfire_analyst, Spotfire_analytics_platform_for_aws, Spotfire_automation_services, Spotfire_connectors, Spotfire_deployment_kit, Spotfire_desktop, Spotfire_desktop_language_packs, Spotfire_professional, Spotfire_web_player 5.4
2015-07-21 CVE-2015-4554 Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Deployment Kit before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Desktop before 6.5.2... Silver_fabric_enabler_for_spotfire_webplayer, Spotfire_analyst, Spotfire_analytics_platform_for_aws, Spotfire_automation_services, Spotfire_deployment_kit, Spotfire_desktop, Spotfire_desktop_language_packs, Spotfire_professional, Spotfire_web_player N/A
2014-04-09 CVE-2014-2544 Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1;... Analyst, Automation_services, Deployment_kit, Desktop, Spotfire_professional, Spotfire_server, Web_player N/A
2012-03-13 CVE-2012-0690 TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a crafted URL. Spotfire_analytics_server, Spotfire_professional, Spotfire_server, Web_player_automation_services N/A