Tibco
Tibco Spotfire Statistics Services: vulnerabilidades y CVE
Tibco Spotfire Statistics Services tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-3115 | Crítica (9.4) | 0.67% | — | 9 abr 2025 | Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable… |
| CVE-2023-29268 | Crítica (9.8) | 1.0% | — | 26 abr 2023 | The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server… |
| CVE-2021-28830 | Alta (7.8) | 0.25% | — | 29 jun 2021 | The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime… |
| CVE-2021-23275 | Alta (7.8) | 0.22% | — | 29 jun 2021 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO… |
| CVE-2019-11204 | Alta (8.8) | 1.5% | — | 14 may 2019 | The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the… |
| CVE-2018-12410 | Crítica (9.8) | 4.0% | — | 10 oct 2018 | The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to… |
| CVE-2013-2371 | Media (5) | 2.0% | — | 15 mar 2013 | The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Tibco
Spotfire Server · 29Jasperreports Server · 23Spotfire Analytics Platform FOR AWS · 20Rendezvous · 16Spotfire Analyst · 13Enterprise Message Service · 12Jaspersoft · 10Managed File Transfer Internet Server · 10Jaspersoft Reporting AND Analytics · 10Managed File Transfer Command Center · 10Spotfire Desktop · 10Runtime Agent · 9