CVE Vulnerabilities

CVE-2023-26221

Insufficiently Protected Credentials

Published: Nov 08, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.9
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Spotfire Connectors component of TIBCO Software Inc.s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Spotfire_analystTibco12.3.0 (including)12.3.0 (including)
Spotfire_analystTibco12.4.0 (including)12.4.0 (including)
Spotfire_analystTibco12.5.0 (including)12.5.0 (including)
Spotfire_analytics_platformTibco12.5.0 (including)12.5.0 (including)
Spotfire_serverTibco12.3.0 (including)12.3.0 (including)
Spotfire_serverTibco12.4.0 (including)12.4.0 (including)
Spotfire_serverTibco12.5.0 (including)12.5.0 (including)

Potential Mitigations

References