LiveActive security incident?Get immediate response
CVE Record

CVE-2017-3180: Multiple TIBCO Spotfire components fail to sanitize user-supplied inout and are vulnerable to cross-site scripting

Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks. The products and versions that are affected include the following: TIBCO Silver Fabric Enabler for Spotfire Web Player 2.1.2 and earlier TIBCO Spotfire Analyst 7.5.0 TIBCO Spotfire Analyst 7.6.0 TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Analytics Platform for AWS Marketplace 7.0.2 and earlier TIBCO Spotfire Automation Services 6.5.3 and earlier TIBCO Spotfire Automation Services 7.0.0, and 7.0.1 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 6.5.3 and earlier TIBCO Spotfire Deployment Kit 7.0.0, and 7.0.1 TIBCO Spotfire Deployment Kit 7.5.0 TIBCO Spotfire Deployment Kit 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spotfire Desktop 6.5.2 and earlier TIBCO Spotfire Desktop 7.0.0, and 7.0.1 TIBCO Spotfire Desktop 7.5.0 TIBCO Spotfire Desktop 7.6.0 TIBCO Spotfire Desktop 7.7.0 TIBCO Spotfire Desktop Developer Edition 7.7.0 TIBCO Spotfire Desktop Language Packs 7.0.1 and earlier TIBCO Spotfire Desktop Language Packs 7.5.0 TIBCO Spotfire Desktop Language Packs 7.6.0 TIBCO Spotfire Desktop Language Packs 7.7.0 TIBCO Spotfire Professional 6.5.3 and earlier TIBCO Spotfire Professional 7.0.0 and 7.0.1 TIBCO Spotfire Web Player 6.5.3 and earlier TIBCO Spotfire Web Player 7.0.0 and 7.0.1

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2017-3180 is a set of cross-site scripting issues across older TIBCO Spotfire products. A successful attack could run script in a user's browser within the trusted Spotfire site, potentially exposing session cookies or enabling follow-on actions. The source bundle does not provide CVSS scoring or fixed-version details.

Executive priority

Treat this as a targeted legacy-platform cleanup item with elevated priority where Spotfire is exposed to many users or the internet. The main business risk is account/session compromise within business analytics environments, but public evidence does not support emergency active-exploitation handling.

Technical view

Multiple TIBCO Spotfire components failed to properly sanitize user-supplied input, mapped to CWE-20. The issue affects several Spotfire desktop, server, web player, deployment, automation, connector, language pack, AWS Marketplace, and Silver Fabric Enabler versions listed in the CVE record.

Likely exposure

Exposure is most likely in organizations still running the listed legacy Spotfire 6.5.x, 7.0.x, 7.5.0, 7.6.0, 7.7.0, or related components. Browser-facing Web Player and AWS Marketplace deployments deserve first review because user browser context is central to the impact.

Exploitation context

The provided sources do not report active exploitation, and the CVE is not marked KEV. The described abuse requires script execution in an unsuspecting user's browser in the affected site's context. Public details are incomplete and do not specify exact inputs, endpoints, or exploit maturity.

Researcher notes

The record is broad and describes multiple unspecified XSS flaws without endpoint detail, CVSS metrics, or explicit fixed versions in the supplied bundle. Validation should focus on asset/version confirmation and vendor advisory correlation, not exploit reproduction. Avoid assuming unlisted Spotfire versions are affected.

Mitigation direction

  • Review the TIBCO advisory for vendor-approved fixed versions or compensating guidance.
  • Inventory all Spotfire products and versions against the CVE affected list.
  • Prioritize remediation for internet-facing Web Player and shared analytics deployments.
  • Retire or isolate unsupported Spotfire versions that cannot be upgraded.
  • Review session cookie protections and least-privilege access around Spotfire users.

Validation and detection

  • Confirm installed Spotfire component names and exact versions.
  • Compare findings against the affected products and versions in the CVE record.
  • Identify whether Spotfire Web Player or analytics services are externally reachable.
  • Check vendor advisory and change records for completed remediation.
  • Review web logs for unusual Spotfire user activity without attempting exploitation.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-20: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2017-3180 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
TIBCOSilver Fabric Enabler for Spotfire Web Player2.1.2Listed
TIBCOSpotfire Analyst7.5.0, 7.6.0, 7.7.0Listed
TIBCOSpotfire Analytics Platform for AWS Marketplace7.0.2Listed
TIBCOSpotfire Automation Services 67.0.0, 7.0.1, 6.5.3Listed
TIBCOSpotfire Connectors7.6.0Listed
TIBCOSpotfire Deployment Kit7.0.0, 7.0.1, 7.5.0, 7.6.0, 7.7.0, 6.5.3Listed
TIBCOSpotfire Desktop7.0.0, 7.0.1, 7.5.0, 7.6.0, 7.7.0, 6.5.2Listed
TIBCOSpotfire Desktop Developer Edition7.7.0Listed
TIBCOSpotfire Desktop Language Packs7.5.0, 7.6.0, 7.7.0, 7.0.1Listed
TIBCOSpotfire Professional7.0.0, 7.0.1, 6.5.3Listed
TIBCOSpotfire Web Player7.0.0, 7.0.1, 6.5.3Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-20 · source CWE mapping

Improper Input Validation

Improper Input Validation represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.