CVE-2014-2544: TIBCO Analyst
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Web Player 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Automation Services 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Deployment Kit 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.1; Spotfire Desktop 6.x before 6.0.1; and Spotfire Analyst 6.x before 6.0.1 allows remote attackers to execute arbitrary code via unknown vectors.
Affected products
- TIBCO Analyst: up to and including 6.0.0
- TIBCO Automation Services: up to and including 4.0.3; version 4.5.0 only; version 4.5.1 only; version 5.0.0 only; version 5.0.1 only; version 5.5.0 only; …
- TIBCO Deployment Kit: up to and including 4.0.3; version 4.5.0 only; version 4.5.1 only; version 5.0.0 only; version 5.0.1 only; version 5.5.0 only; …
- TIBCO Desktop: up to and including 6.0.0
- TIBCO Spotfire Professional: up to and including 4.0.3; version 4.5.0 only; version 4.5.1 only; version 5.0.0 only; version 5.0.1 only; version 5.5.0 only; …
- TIBCO Spotfire Server: up to and including 3.3.3; version 4.5.0 only; version 5.0.0 only; version 5.0.1 only; version 5.5.0 only; version 6.0.0 only; …
- TIBCO Web Player: up to and including 4.0.3; version 4.5.0 only; version 4.5.1 only; version 5.0.0 only; version 5.0.1 only; version 5.5.0 only; …
Published 2014-04-10. Last modified 2026-06-17.