TIBCO Software Inc. maintains a broadly represented portfolio of enterprise analytics, messaging, and integration platforms that span data visualization, reporting, and real-time event processing across cloud and on-premises deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure concentrates in flagship products such as Spotfire Server, JasperReports Server, and the Spotfire Analytics Platform and recurs through weakness classes including cross-site scripting, cross-site request forgery, and improper handling of sensitive information that are characteristic of large, web-facing enterprise applications. The vendor's disclosures reflect both direct application flaws and placeholder classifications that span the breadth of its middleware and analytics stack. Defenders should treat TIBCO advisories as broadly applicable to data-tier and integration infrastructure and prioritize patches for internet-reachable instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by TIBCO Software Inc. over time
Of all the CVEs published by TIBCO Software Inc. as a CNA, 93.1% affect products that TIBCO Software Inc. develops as a vendor.
Of all the CVEs published that affect products developed by TIBCO Software Inc., 71.5% are self-published by TIBCO Software Inc. as a CNA.
Signals from CVEs in this vendor scope (228 CVEs).
228 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18809MEDIUM The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix | Mar 7, 2019 | 6.5 | 94 | YES | YES |
CVE-2018-5430HIGH The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspe | Apr 17, 2018 | 8.8 | 91 | YES | YES |
CVE-2020-9409CRITICAL The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix | May 20, 2020 | 9.8 | 32 | NO | NO |
CVE-2018-18815CRITICAL The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jas | Mar 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-5435CRITICAL The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TI | Jun 27, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-3207CRITICAL Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. | Mar 17, 2026 | 9.8 | 31 | NO | NO |
CVE-2021-43049CRITICAL The Database component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with ne | Feb 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-9412CRITICAL The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary | Jun 9, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-11208CRITICAL The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that t | Aug 8, 2019 | 9.9 | 31 | NO | NO |
CVE-2018-12410CRITICAL The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to auth | Oct 10, 2018 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (228 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by TIBCO Software Inc..
Media articles that mention a CVE ID that affects a product developed by TIBCO Software Inc. — matched by CVE ID, not by vendor name.