Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-2544


Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Automation Services 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Deployment Kit 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Desktop 6.x before 6.0.1; and Spotfire Analyst 6.x before 6.0.1 allows remote attackers to execute arbitrary code via unknown vectors.


Published

2014-04-10T00:55:09.937

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tibco web_player ≤ 4.0.3 Yes
Application tibco web_player 4.5.0 Yes
Application tibco web_player 4.5.1 Yes
Application tibco web_player 5.0.0 Yes
Application tibco web_player 5.0.1 Yes
Application tibco web_player 5.5.0 Yes
Application tibco web_player 6.0.0 Yes
Application tibco automation_services ≤ 4.0.3 Yes
Application tibco automation_services 4.5.0 Yes
Application tibco automation_services 4.5.1 Yes
Application tibco automation_services 5.0.0 Yes
Application tibco automation_services 5.0.1 Yes
Application tibco automation_services 5.5.0 Yes
Application tibco automation_services 6.0.0 Yes
Application tibco spotfire_server ≤ 3.3.3 Yes
Application tibco spotfire_server 4.5.0 Yes
Application tibco spotfire_server 5.0.0 Yes
Application tibco spotfire_server 5.0.1 Yes
Application tibco spotfire_server 5.5.0 Yes
Application tibco spotfire_server 6.0.0 Yes
Application tibco spotfire_server 6.0.1 Yes
Application tibco spotfire_professional ≤ 4.0.3 Yes
Application tibco spotfire_professional 4.5.0 Yes
Application tibco spotfire_professional 4.5.1 Yes
Application tibco spotfire_professional 5.0.0 Yes
Application tibco spotfire_professional 5.0.1 Yes
Application tibco spotfire_professional 5.5.0 Yes
Application tibco spotfire_professional 6.0.0 Yes
Application tibco analyst ≤ 6.0.0 Yes
Application tibco desktop ≤ 6.0.0 Yes
Application tibco deployment_kit ≤ 4.0.3 Yes
Application tibco deployment_kit 4.5.0 Yes
Application tibco deployment_kit 4.5.1 Yes
Application tibco deployment_kit 5.0.0 Yes
Application tibco deployment_kit 5.0.1 Yes
Application tibco deployment_kit 5.5.0 Yes
Application tibco deployment_kit 6.0.0 Yes

References