Input validation error in TIBCO products - CVE-2019-17334

 

Input validation error in TIBCO products - CVE-2019-17334

Published: December 18, 2019


Vulnerability identifier: #VU23655
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17334
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the Visualizations component when processing DXP files. A remote attacker can trick a victim to store the DXP files to the Spotfire library and execute arbitrary code on the target system.


Affected software

TIBCO Spotfire Desktop Language Packs
TIBCO Spotfire Deployment Kit
TIBCO Spotfire Desktop
TIBCO Spotfire Analyst
TIBCO Spotfire for AWS

How to mitigate CVE-2019-17334

Install updates from vendor's website.

TIBCO Spotfire Desktop Language Packs - update to 7.11.2
TIBCO Spotfire Deployment Kit - update to 7.11.2
TIBCO Spotfire Analyst - addressed in versions 7.11.2, 10.3.3, 10.6.1
TIBCO Spotfire Desktop - addressed in versions 7.11.2, 10.3.3, 10.6.1
TIBCO Spotfire for AWS - update to 10.6.1

External References

Related Security Bulletins