MEDIUM · 4.0

CVE-2014-7195

Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spot...

Vulnerability Description

Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
TibcoSilver Fabric Enabler<= 1.6.0
TibcoSpotfire Deployment Kit6.0.0
TibcoSpotfire Web Player6.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-7195?

CVE-2014-7195 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spot...

How severe is CVE-2014-7195?

CVE-2014-7195 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-7195?

Check the references section above for vendor advisories and patch information. Affected products include: Tibco Silver Fabric Enabler, Tibco Spotfire Deployment Kit, Tibco Spotfire Web Player.