Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3181


Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The following products and versions are affected: TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spotfire Desktop 7.6.0 TIBCO Spotfire Desktop 7.7.0 TIBCO Spotfire Desktop Developer Edition 7.7.0 TIBCO Spotfire Desktop Language Packs 7.6.0 TIBCO Spotfire Desktop Language Packs 7.7.0 The following components are affected: TIBCO Spotfire Client TIBCO Spotfire Web Player Client


Published

2018-07-24T15:29:00.373

Last Modified

2024-11-21T03:24:58.837

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tibco spotfire_analyst 7.7.0 Yes
Application tibco spotfire_client - Yes
Application tibco spotfire_connectors 7.6.0 Yes
Application tibco spotfire_deployment_kit 7.7.0 Yes
Application tibco spotfire_desktop 7.6.0 Yes
Application tibco spotfire_desktop 7.7.0 Yes
Application tibco spotfire_desktop 7.7.0 Yes
Application tibco spotfire_desktop_language_packs 7.6.0 Yes
Application tibco spotfire_desktop_language_packs 7.7.0 Yes
Application tibco spotfire_web_player_client - Yes

References