Critical severity10.0NVD Advisory· Published Sep 18, 2019· Updated Jun 17, 2026
CVE-2019-11210
CVE-2019-11210
Description
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.
Affected products
7- cpe:2.3:a:tibco:enterprise_runtime_for_r:*:*:*:*:server:*:*:*Range: <=1.2.0
cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:10.4.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:10.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:10.5.0:*:*:*:*:*:*:*
- (no CPE)range: 10.4.0
1.2.0 and below+ 1 more
- (no CPE)range: 1.2.0 and below
- (no CPE)range: <=1.2.0
- Range: 10.4.0, 10.5.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.