Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2544

Опубликовано: 10 апр. 2014
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Automation Services 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Deployment Kit 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Desktop 6.x before 6.0.1; and Spotfire Analyst 6.x before 6.0.1 allows remote attackers to execute arbitrary code via unknown vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tibco:web_player:*:*:*:*:*:*:*:*
Версия до 4.0.3 (включая)
cpe:2.3:a:tibco:web_player:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:web_player:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:web_player:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:web_player:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:web_player:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:web_player:6.0.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:tibco:automation_services:*:*:*:*:*:*:*:*
Версия до 4.0.3 (включая)
cpe:2.3:a:tibco:automation_services:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:automation_services:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:automation_services:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:automation_services:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:automation_services:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:automation_services:6.0.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:*
Версия до 3.3.3 (включая)
cpe:2.3:a:tibco:spotfire_server:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.1:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:tibco:spotfire_professional:*:*:*:*:*:*:*:*
Версия до 4.0.3 (включая)
cpe:2.3:a:tibco:spotfire_professional:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_professional:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_professional:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_professional:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_professional:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_professional:6.0.0:*:*:*:*:*:*:*
Конфигурация 5

Одно из

cpe:2.3:a:tibco:analyst:*:*:*:*:*:*:*:*
Версия до 6.0.0 (включая)
cpe:2.3:a:tibco:desktop:*:*:*:*:*:*:*:*
Версия до 6.0.0 (включая)
Конфигурация 6

Одно из

cpe:2.3:a:tibco:deployment_kit:*:*:*:*:*:*:*:*
Версия до 4.0.3 (включая)
cpe:2.3:a:tibco:deployment_kit:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:deployment_kit:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:deployment_kit:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:deployment_kit:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:deployment_kit:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:deployment_kit:6.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01175
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Automation Services 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Deployment Kit 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Desktop 6.x before 6.0.1; and Spotfire Analyst 6.x before 6.0.1 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS

Процентиль: 78%
0.01175
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo