Information disclosure in TIBCO Spotfire Statistics Services - CVE-2019-11204
Published: September 20, 2019
TIBCO Spotfire Statistics Services
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the web interface component exposes sensitive files. A remote authenticated attacker can gain unauthorized access to sensitive information on the target system, such as database, JMX, LDAP, Windows service account, and user credentials.