5.4
CVSSv3

CVE-2017-3180

Published: 24/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the malicious user to steal cookie-based authentication credentials and to launch other attacks. The products and versions that are affected include the following: TIBCO Silver Fabric Enabler for Spotfire Web Player 2.1.2 and previous versions TIBCO Spotfire Analyst 7.5.0 TIBCO Spotfire Analyst 7.6.0 TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Analytics Platform for AWS Marketplace 7.0.2 and previous versions TIBCO Spotfire Automation Services 6.5.3 and previous versions TIBCO Spotfire Automation Services 7.0.0, and 7.0.1 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 6.5.3 and previous versions TIBCO Spotfire Deployment Kit 7.0.0, and 7.0.1 TIBCO Spotfire Deployment Kit 7.5.0 TIBCO Spotfire Deployment Kit 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spotfire Desktop 6.5.2 and previous versions TIBCO Spotfire Desktop 7.0.0, and 7.0.1 TIBCO Spotfire Desktop 7.5.0 TIBCO Spotfire Desktop 7.6.0 TIBCO Spotfire Desktop 7.7.0 TIBCO Spotfire Desktop Developer Edition 7.7.0 TIBCO Spotfire Desktop Language Packs 7.0.1 and previous versions TIBCO Spotfire Desktop Language Packs 7.5.0 TIBCO Spotfire Desktop Language Packs 7.6.0 TIBCO Spotfire Desktop Language Packs 7.7.0 TIBCO Spotfire Professional 6.5.3 and previous versions TIBCO Spotfire Professional 7.0.0 and 7.0.1 TIBCO Spotfire Web Player 6.5.3 and previous versions TIBCO Spotfire Web Player 7.0.0 and 7.0.1

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tibco spotfire automation services

tibco spotfire automation services 7.0.0

tibco spotfire automation services 7.0.1

tibco spotfire connectors 7.6.0

tibco spotfire desktop language packs

tibco spotfire desktop language packs 7.5.0

tibco spotfire desktop language packs 7.6.0

tibco spotfire desktop language packs 7.7.0

tibco spotfire analyst 7.6.0

tibco spotfire analytics platform for aws

tibco spotfire deployment kit

tibco spotfire deployment kit 7.0.1

tibco spotfire deployment kit 7.6.0

tibco spotfire desktop 7.5.0

tibco spotfire desktop 7.7.0

tibco spotfire professional 7.0.0

tibco spotfire web player

tibco silver fabric enabler for spotfire web player

tibco spotfire deployment kit 7.7.0

tibco spotfire desktop

tibco spotfire desktop 7.0.0

tibco spotfire desktop 7.0.1

tibco spotfire web player 7.0.0

tibco spotfire web player 7.0.1

tibco spotfire analyst 7.5.0

tibco spotfire analyst 7.7.0

tibco spotfire deployment kit 7.0.0

tibco spotfire deployment kit 7.5.0

tibco spotfire desktop 7.6.0

tibco spotfire professional

tibco spotfire professional 7.0.1