Skip to main content

Vendor archive

tibco CVEs

Beta · best-effort

225 CVEs tagged to vendor tibco42 Critical, 100 High, 82 Medium, 1 Low, 0 Unrated.

CVE-2013-3315

Published May 31, 2013

The server in TIBCO Silver Mobile 1.1.0 does not properly verify access to the administrator role before executing a command, which allows authenticated users to gain privileges v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2373

Published Mar 15, 2013

The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implement access control, which allows…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2372

Published Mar 15, 2013

Cross-site scripting (XSS) vulnerability in the Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remot…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2371

Published Mar 15, 2013

The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensiti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5302

Published Oct 24, 2012

The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0687

Published Mar 13, 2012

TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fab…

CVSS 5.0 · Medium

CVE-2011-2021

Published May 20, 2011

Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1414

Published Mar 22, 2011

Cross-site scripting (XSS) vulnerability in the tibbr web server, as used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0 through 1.5.0, allows remote attackers to inje…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 225 CVEsPage 8 of 9