TIBCO Software Inc.

First CVE: May 9, 2017Active for: 9 years
175
CVEs Published
More CVEs Published than 78% of tracked CNAs
17.5
Avg CVEs / Year
More Avg CVEs / Year than 64% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked CNAs
1.1%
In CISA KEV
Higher KEV Rate than 88% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by TIBCO Software Inc. as a CNA, 93.1% affect products that TIBCO Software Inc. develops as a vendor.

93.1%
Self-reported: 163Third-party: 12

Of all the CVEs published that affect products developed by TIBCO Software Inc., 71.5% are self-published by TIBCO Software Inc. as a CNA.

71.5%
28.5%
Self-published: 163Published by other CNAs: 65

Trends Over Time

The number and severity of CVEs published by TIBCO Software Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2017
9 years ago
Most Recent CVE
Mar 24, 2026
122 days ago

Top CVEs

All CVEs published by TIBCO Software Inc. as a CNA, regardless of affected vendor or product.

175 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix
Mar 7, 20196.594YESYES
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspe
Apr 17, 20188.891YESYES
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix
May 20, 20209.832NONO
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jas
Mar 7, 20199.832NONO
The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TI
Jun 27, 20189.832NONO
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
Mar 17, 20269.831NONO
Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution
Jun 27, 20249.931NONO
The Database component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with ne
Feb 15, 20229.831NONO
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary
Jun 9, 20209.831NONO
The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that t
Aug 8, 20199.931NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA175 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local17 (9.7%)
Network157 (89.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.6%)
Attack Complexity
Low166 (94.9%)
High9 (5.1%)
Unknown0 (0.0%)
User Interaction
None101 (57.7%)
Unknown0 (0.0%)
Required70 (40.0%)
Privileges Required
Low114 (65.1%)
High8 (4.6%)
None53 (30.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (175 CVEs).

CISA KEV
2 CVEs
1.1% of CVEs· 88th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.6% of CVEs· 76th percentile
ExploitDB
1 CVE
0.6% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by TIBCO Software Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by TIBCO Software Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs