CVE-2018-5435

TIBCO Spotfire Product Family Remote Code Execution Vulnerability

Description

The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

Remediation

Solution:

  • TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Spotfire Analyst versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Analyst versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Analyst versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Analyst version 7.11.0 update to version 7.11.1 TIBCO Spotfire Analyst version 7.12.0 update to version 7.13.0 TIBCO Spotfire Analytics Platform for AWS Marketplace versions 7.12.0 and below update to version 7.13.0 or higher TIBCO Spotfire Deployment Kit versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Deployment Kit versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Deployment Kit versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Deployment Kit version 7.11.0 update to version 7.11.1 or higher TIBCO Spotfire Deployment Kit version 7.12.0 update to version 7.13.0 or higher TIBCO Spotfire Desktop versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Desktop versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Desktop versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Desktop version 7.11.0 update to version 7.11.1 or higher TIBCO Spotfire Desktop version 7.12.0 update to version 7.13.0 or higher TIBCO Spotfire Desktop Language Packs versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Desktop Language Packs versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Desktop Language Packs versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Desktop Language Packs version 7.11.0 update to version 7.11.1 or higher
9.6
CVSS
Severity: Critical
CVSS 3.0 •
CVSS 2.0 •
EPSS 1.48% Top 25%
Vendor Advisory tibco.com Vendor Advisory tibco.com
Affected: TIBCO Software Inc. TIBCO Spotfire Analyst
Affected: TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace
Affected: TIBCO Software Inc. TIBCO Spotfire Deployment Kit
Affected: TIBCO Software Inc. TIBCO Spotfire Desktop
Affected: TIBCO Software Inc. TIBCO Spotfire Desktop Language Packs
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2018-5435?
CVE-2018-5435 has been scored as a critical severity vulnerability.
How to fix CVE-2018-5435?
To fix CVE-2018-5435: TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Spotfire Analyst versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Analyst versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Analyst versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Analyst version 7.11.0 update to version 7.11.1 TIBCO Spotfire Analyst version 7.12.0 update to version 7.13.0 TIBCO Spotfire Analytics Platform for AWS Marketplace versions 7.12.0 and below update to version 7.13.0 or higher TIBCO Spotfire Deployment Kit versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Deployment Kit versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Deployment Kit versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Deployment Kit version 7.11.0 update to version 7.11.1 or higher TIBCO Spotfire Deployment Kit version 7.12.0 update to version 7.13.0 or higher TIBCO Spotfire Desktop versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Desktop versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Desktop versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Desktop version 7.11.0 update to version 7.11.1 or higher TIBCO Spotfire Desktop version 7.12.0 update to version 7.13.0 or higher TIBCO Spotfire Desktop Language Packs versions 7.8.0 and below update to version 7.8.1 or higher TIBCO Spotfire Desktop Language Packs versions 7.9.0 and 7.9.1 update to version 7.9.2 or higher TIBCO Spotfire Desktop Language Packs versions 7.10.0 and 7.10.1 update to version 7.10.2 or higher TIBCO Spotfire Desktop Language Packs version 7.11.0 update to version 7.11.1 or higher
Is CVE-2018-5435 being actively exploited in the wild?
It is possible that CVE-2018-5435 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2018-5435?
CVE-2018-5435 affects TIBCO Software Inc. TIBCO Spotfire Analyst, TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Software Inc. TIBCO Spotfire Deployment Kit, TIBCO Software Inc. TIBCO Spotfire Desktop, TIBCO Software Inc. TIBCO Spotfire Desktop Language Packs.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.