CVE-2023-26221 - CVE House
Back to Database
Status published Medium CVE-2023-26221

TIBCO Spotfire Insufficiently Protected Credential vulnerability

Vulnerability Description

The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-26221

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

TIBCO Software Inc.

View all reports →

Affected Software

Spotfire Analyst, Spotfire Server, Spotfire for AWS Marketplace
Vulnerable Versions:
12.3.0, 12.4.0, 12.5.0

Timeline

Official Publish: November 8th, 2023
Last Modified: September 4th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)