CVE-2023-29268

EUVD-2023-32843
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
tibcoCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
tibcospotfire_statistics_services
𝑥
< 11.4.11
tibcospotfire_statistics_services
11.5.0
tibcospotfire_statistics_services
11.6.0
tibcospotfire_statistics_services
11.6.1
tibcospotfire_statistics_services
11.6.2
tibcospotfire_statistics_services
11.7.0
tibcospotfire_statistics_services
11.8.0
tibcospotfire_statistics_services
11.8.1
tibcospotfire_statistics_services
12.0.0
tibcospotfire_statistics_services
12.0.1
tibcospotfire_statistics_services
12.0.2
tibcospotfire_statistics_services
12.1.0
tibcospotfire_statistics_services
12.2.0
𝑥
= Vulnerable software versions