Information disclosure in TIBCO Spotfire Statistics Services - CVE-2019-11204

 

Information disclosure in TIBCO Spotfire Statistics Services - CVE-2019-11204

Published: September 20, 2019


Vulnerability identifier: #VU21221
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2019-11204
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the web interface component exposes sensitive files. A remote authenticated attacker can gain unauthorized access to sensitive information on the target system, such as database, JMX, LDAP, Windows service account, and user credentials.


Affected software

TIBCO Spotfire Statistics Services

How to mitigate CVE-2019-11204

Install updates from vendor's website.

TIBCO Spotfire Statistics Services - addressed in versions 7.11.2, 10.0.1

External References

Related Security Bulletins