CVE-2015-5712
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated…
Does this matter?
Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.
Description
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- tibco/spotfire analytics platform for aws · tibco/spotfire server
- Source
- cve@mitre.org
References
- http://www.securitytracker.com/id/1034011
- http://www.tibco.com/assets/blt3a3a55ab42f2f5cd/2015-004-advisory.txtVendor Advisory
- http://www.tibco.com/mk/advisory.jspVendor Advisory
- http://www.securitytracker.com/id/1034011
- http://www.tibco.com/assets/blt3a3a55ab42f2f5cd/2015-004-advisory.txtVendor Advisory
- http://www.tibco.com/mk/advisory.jspVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.