Back

CVE-2019-11211

CRITICAL

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.

Published: Sep 18, 2019 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: LOW User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
tibco enterprise_runtime_for_r *
tibco spotfire_analytics_platform_for_aws 10.4.0
tibco spotfire_analytics_platform_for_aws 10.5.0

GitHub Security Advisory GHSA-9636-qqqx-549h

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition,...

Risk Scores

CVSS Score 9.9 / 10
EPSS Score 3.72%

Top 11% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub