VulnerabilityModified
CVE-2013-2371
The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.
MEDIUM 5.0EPSS 2.05%
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- tibco/spotfire statistics services
- Source
- cve@mitre.org
References
- http://www.tibco.com/mk/advisory.jspVendor Advisory
- http://www.tibco.com/multimedia/spotfire-statistics-services-advisory-2013-03-12_tcm8-18479.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/spotfire-advisory_20130313.jspVendor Advisory
- http://www.tibco.com/mk/advisory.jspVendor Advisory
- http://www.tibco.com/multimedia/spotfire-statistics-services-advisory-2013-03-12_tcm8-18479.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/spotfire-advisory_20130313.jspVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.