Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5712

Опубликовано: 28 окт. 2015
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:*:*:*:*:*:*:*:*
Версия до 7.0.1 (включая)
Конфигурация 2

Одно из

cpe:2.3:a:tibco:spotfire_server:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.0.4:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:6.5.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_server:7.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.0032
Низкий

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.

EPSS

Процентиль: 55%
0.0032
Низкий

4 Medium

CVSS2

Дефекты

CWE-200