Insufficiently protected credentials in TIBCO products - CVE-2023-26221
Published: November 9, 2023
Vulnerability identifier: #VU82925
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26221
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficiently protected credentials in the Spotfire Connectors component. A remote attacker can use a specially crafted Analyst file and obtain access tokens of authorized users.
Affected software
TIBCO Spotfire Analyst
TIBCO Spotfire Server
TIBCO Spotfire for AWS
TIBCO Spotfire Server
TIBCO Spotfire for AWS
How to mitigate CVE-2023-26221
Install updates from vendor's website.
TIBCO Spotfire Analyst - update to 14.0.0
TIBCO Spotfire Server - update to 14.0.0
TIBCO Spotfire for AWS - update to 14.0.0
TIBCO Spotfire Server - update to 14.0.0
TIBCO Spotfire for AWS - update to 14.0.0