cvedb.io
CVE-2018-12410
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2018-10-10T20:29:00.273 · Last modified 2026-06-17T01:37:44.280

Summary

The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component. Affected releases are TIBCO Software Inc. TIBCO Spotfire Statistics Services versions up to and including 7.11.0.

Affected products

tibco — spotfire_statistics_services

Does this affect you?

Add your gear to cvedb and we'll alert you only when tibco ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.