CVE-2012-0690: TIBCO Spotfire Analytics Server
Medium severity, CVSS 5.0. EPSS: 1.6% chance of exploitation in the next 30 days.
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a crafted URL.
Affected products
- TIBCO Spotfire Analytics Server: version 10.0.0 only; version 10.0.1 only
- TIBCO Spotfire Professional: up to and including 4.0.1
- TIBCO Spotfire Server: version 3.0.0 only; version 3.0.1 only; version 3.1.0 only; version 3.1.1 only; version 3.2.0 only; version 3.3.0 only
- TIBCO Web Player Automation Services: any version
Published 2012-03-13. Last modified 2026-06-16.