CVE-2013-2373
EUVD-2013-231915.03.2013, 22:55
The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tibco | spotfire_web_player | 3.3 |
| tibco | spotfire_web_player | 3.3.2 |
| tibco | spotfire_web_player | 4.0 |
| tibco | spotfire_web_player | 4.0.1 |
| tibco | spotfire_web_player | 4.0.2 |
| tibco | spotfire_web_player | 4.5.0 |
| tibco | spotfire_web_player | 5.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References