CVE Published: 26/11/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO Statistica Server Status : PUBLISHED
CVE-2018-18807 Description
The web application of the TIBCO Statistica component of TIBCO Software Inc.\'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.\'s TIBCO Statistica Server versions up to and including 13.4.0.
CWE-ID: CWE Name: The impact of this vulnerability includes the theoretical possibility that an authenticated user could escalate privileges to gain administrative access to the web interface of the affected component. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)