CVE-2023-29268

The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
tibcoCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
tibcospotfire_statistics_services
𝑥
< 11.4.11
tibcospotfire_statistics_services
11.5.0
tibcospotfire_statistics_services
11.6.0
tibcospotfire_statistics_services
11.6.1
tibcospotfire_statistics_services
11.6.2
tibcospotfire_statistics_services
11.7.0
tibcospotfire_statistics_services
11.8.0
tibcospotfire_statistics_services
11.8.1
tibcospotfire_statistics_services
12.0.0
tibcospotfire_statistics_services
12.0.1
tibcospotfire_statistics_services
12.0.2
tibcospotfire_statistics_services
12.1.0
tibcospotfire_statistics_services
12.2.0
𝑥
= Vulnerable software versions