Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.87% | — | Tibco Activespaces | 6/11/2018 | 17/6/2026 | The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are… | |
| Modificada | Crítica (9.8) | 4.0% | — | Tibco Spotfire Statistics Services | 10/10/2018 | 17/6/2026 | The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component.… | |
| Modificada | Alta (7.5) | 2.4% | — | Tibco Activematrix BusinessworksActivematrix Businessworks Distribution FOR Tibco Silver Fabric | 8/8/2018 | 17/6/2026 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages,… | |
| Modificada | Crítica (9.8) | 1.7% | — | Tibco Spotfire AnalystTibco Spotfire ClientTibco Spotfire ConnectorsTibco Spotfire Deployment KIT+3 | 24/7/2018 | 17/6/2026 | Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in… | |
| Modificada | Media (5.4) | 0.61% | — | Tibco Silver Fabric Enabler FOR Spotfire WEB PlayerTibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Automation Services+6 | 24/7/2018 | 17/6/2026 | Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the… | |
| Modificada | Alta (8.8) | 0.93% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 27/6/2018 | 17/6/2026 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may… | |
| Modificada | Alta (8.8) | 1.0% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 27/6/2018 | 17/6/2026 | The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Crítica (9.8) | 3.2% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 27/6/2018 | 17/6/2026 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may… | |
| Modificada | Alta (8.8) | 3.0% | — | Tibco Data Virtualization | 20/6/2018 | 17/6/2026 | The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data Virtualization: 7.0.5; 7.0.6. | |
| Modificada | Media (6.5) | 1.2% | — | Tibco Runtime Agent | 13/6/2018 | 17/6/2026 | The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime… | |
| Modificada | Media (6.5) | 1.4% | — | Tibco Administrator | 13/6/2018 | 17/6/2026 | The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected… | |
| Modificada | Media (5.4) | 0.86% | — | Tibco Administrator | 13/6/2018 | 17/6/2026 | The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains multiple vulnerabilities wherein a malicious user could theoretically perform cross-site scripting (XSS) attacks by way of manipulating… | |
| Modificada | Media (5.4) | 0.68% | — | Tibco Datasynapse Gridserver Manager | 1/5/2018 | 17/6/2026 | The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack.… | |
| Modificada | Media (6.8) | 0.18% | — | Tibco Datasynapse Gridserver Manager | 1/5/2018 | 17/6/2026 | The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ciphers. A malicious actor could theoretically compromise the traffic between any… | |
| Modificada | Media (5.4) | 0.59% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 17/4/2018 | 17/6/2026 | The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow,… | |
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 Exploit | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 17/4/2018 | 17/6/2026 | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any… | |
| Modificada | Alta (8.8) | 1.5% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 17/4/2018 | 17/6/2026 | A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix… | |
| Modificada | Alta (8.8) | 1.3% | — | Tibco Tibbr | 13/12/2017 | 17/6/2026 | The tibbr user profiles components of tibbr Community, and tibbr Enterprise expose a weakness in an improperly sandboxed third-party component. Affected releases are TIBCO Software Inc. tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0. | |
| Modificada | Alta (8.1) | 0.86% | — | Tibco Tibbr | 13/12/2017 | 17/6/2026 | The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1… | |
| Modificada | Media (4.8) | 0.79% | — | Integrationmatters NjamsTibco Businessworks Process Monitor | 11/12/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users management panel of the web interface. | |
| Modificada | Crítica (9.8) | 2.0% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 15/11/2017 | 17/6/2026 | A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent… | |
| Modificada | Media (5.4) | 0.69% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 15/11/2017 | 17/6/2026 | A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft… | |
| Modificada | Alta (8.8) | 1.3% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 17/10/2017 | 17/6/2026 | Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Internet Server versions 8.0.0 and 8.0.1 that enable the Administrator Service may be affected by a vulnerability which may allow any authenticated user to gain administrative control of Managed File… | |
| Modificada | Media (6.5) | 1.3% | — | Tibco Jasperreports Library Community EditionTibco Jasperreports Library FOR Activematrix BPMTibco Jasperreports ProfessionalTibco Jasperreports Server+5 | 29/6/2017 | 17/6/2026 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for… | |
| Modificada | Alta (8.8) | 0.57% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 29/6/2017 | 17/6/2026 | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server… |