CVE-2012-0690 describes an information disclosure vulnerability in multiple TIBCO Spotfire applications, including Web Application, Web Player, Automation Services, and Analytics Client, across several versions. This flaw allows unauthenticated remote attackers to retrieve sensitive information by crafting a specific URL. With a CVSS score of 5.0, it is a medium severity vulnerability, requiring no authentication or complex attack vectors, and primarily impacts confidentiality. Despite its age, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, suggesting a low likelihood of real-world exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_analytics_server:10.0.0:*:*:*:*:*:*:* | ||
10.0.1CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_analytics_server:10.0.1:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:3.0.0:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:3.0.1:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:3.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.