Discover the vulnerability in TIBCO Spotfire Analytics Platform and Spotfire Server allowing a reflected cross-site scripting attack. Learn about affected versions and mitigation steps.
The TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server have identified a vulnerability that could lead to a reflected cross-site scripting (XSS) attack.
Understanding CVE-2019-17337
What is CVE-2019-17337?
The vulnerability in the Spotfire library component of TIBCO Spotfire Analytics Platform and Spotfire Server could allow an attacker to execute a reflected XSS attack.
The Impact of CVE-2019-17337
The vulnerability could potentially grant an attacker full administrative access to the web interface of the affected component.
Technical Details of CVE-2019-17337
Vulnerability Description
The vulnerability lies in the Spotfire library component, enabling a reflected cross-site scripting (XSS) attack.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
TIBCO has released updated versions to address the vulnerability in both the Spotfire Analytics Platform and Spotfire Server.