CVE-2023-29268: TIBCO Spotfire Statistics Services
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.
Affected products
- TIBCO Spotfire Statistics Services: before 11.4.11 (fixed in 11.4.11); version 11.5.0 only; version 11.6.0 only; version 11.6.1 only; version 11.6.2 only; version 11.7.0 only; …
Published 2023-04-26. Last modified 2026-06-17.