The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.
2019-09-18T23:15:10.860
2024-11-21T04:20:44.013
Modified
CVSSv3.1: 10.0 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tibco | enterprise_runtime_for_r | ≤ 1.2.0 | Yes |
Application | tibco | spotfire_analytics_platform_for_aws | 10.4.0 | Yes |
Application | tibco | spotfire_analytics_platform_for_aws | 10.5.0 | Yes |