peter bassill · operator
$ cve CVE-2018-12410 JSON

CVE-2018-12410

9.8
CRITICAL · CVSS 3.0 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component. Affected releases are TIBCO Software Inc. TIBCO Spotfire Statistics Services versions up to and including 7.11.0.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.97% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploitnone known
Published2018-10-10
Last modified2026-06-17

Affected (1)

VendorProduct
tibcospotfire statistics services

References

→ the Explorer  ·  watch your stack  ·  NVD