Back
CVE-2019-11210
CRITICAL
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.
Published: Sep 18, 2019
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| tibco | enterprise_runtime_for_r | * |
| tibco | spotfire_analytics_platform_for_aws | 10.4.0 |
| tibco | spotfire_analytics_platform_for_aws | 10.5.0 |
GitHub Security Advisory GHSA-g2pq-36f3-2p66
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition,...
References (4)
- http://www.tibco.com/services/support/advisories Vendor Advisory
- https://www.tibco.com/support/advisories/2019/09/tibco-security-advisory-september-17-2019-tibco-enterprise-runtime-for-r-server-2019-11210 Vendor Advisory
- http://www.tibco.com/services/support/advisories Vendor Advisory
- https://www.tibco.com/support/advisories/2019/09/tibco-security-advisory-september-17-2019-tibco-enterprise-runtime-for-r-server-2019-11210 Vendor Advisory
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
3.66%
Top 11% most likely to be exploited
Threat Score
41.1 / 100
Data Sources
NVD
EPSS
GitHub