CVE-2019-17337 describes a reflected Cross-Site Scripting (XSS) vulnerability within the Spotfire library component of TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server. This flaw allows an attacker to inject malicious scripts into a web page, which are then executed by a user's browser. The vulnerability affects numerous versions of both TIBCO Spotfire Analytics Platform for AWS Marketplace (version 10.6.0) and TIBCO Spotfire Server (multiple versions across 7.x, 10.x). Rated with a CVSS score of 5.4 (Medium), the attack requires user interaction (UI:R) and has low impacts on confidentiality and integrity (C:L, I:L), with no impact on availability (A:N). The attack complexity is low (AC:L), and it can be launched over the network (AV:N). Currently, there is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.6.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:10.6.0:*:*:*:*:*:*:* | ||
<= 7.11.7CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:*:*:*:*:*:*:*:* | ||
7.12.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:7.12.0:*:*:*:*:*:*:* | ||
7.13.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:7.13.0:*:*:*:*:*:*:* | ||
7.14.0CPE matchmatch criteria | cpe:2.3:a:tibco:spotfire_server:7.14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.