Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29268


The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.


Published

2023-04-26T18:15:09.160

Last Modified

2025-01-30T22:15:07.977

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-434
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tibco spotfire_statistics_services < 11.4.11 Yes
Application tibco spotfire_statistics_services 11.5.0 Yes
Application tibco spotfire_statistics_services 11.6.0 Yes
Application tibco spotfire_statistics_services 11.6.1 Yes
Application tibco spotfire_statistics_services 11.6.2 Yes
Application tibco spotfire_statistics_services 11.7.0 Yes
Application tibco spotfire_statistics_services 11.8.0 Yes
Application tibco spotfire_statistics_services 11.8.1 Yes
Application tibco spotfire_statistics_services 12.0.0 Yes
Application tibco spotfire_statistics_services 12.0.1 Yes
Application tibco spotfire_statistics_services 12.0.2 Yes
Application tibco spotfire_statistics_services 12.1.0 Yes
Application tibco spotfire_statistics_services 12.2.0 Yes

References