Release date:
Updated on: 2013-03-16
Affected Systems:
TIBCO Spotfire Statistics Services 5.x
TIBCO Spotfire Statistics Services 4.x
TIBCO Spotfire Statistics Services 3.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-2371
TIBCO Spotfire Statistics Services is a lightweight data Statistics server.
TIBCO Spotfire Statistics Services 3.3.0, 4.5.0, and 5.0.0 have errors in processing HTTP requests. Attackers can obtain some data through specially crafted HTTP requests.
<* Source: vendor
Link: http://secunia.com/advisories/52578/
Http://www.tibco.com/multimedia/spotfire-statistics-services-advisory-2013-03-12_tcm8-18479.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TIBCO
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://docs.tibco.com/products/tibco-spotfire-statistics-services-5-0-0