← Vulnerability feed

Vulnerability record · CVE-2014-7195 · published 21 November 2014

CVE-2014-7195: Tibco silver fabric enabler information exposure vulnerability

Tibco · Silver Fabric Enabler

Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.

4.0 CVSS 2.0 Medium EPSS 0.94% · top 40.3% CWE-200 · Information exposure
4.0CVSS 2.0 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.

AV:N/AC:L/Au:S/C:P/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-7195 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-8993Tibco activematrix bpm missing authentication for critical function vulnerabilityThe administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric,…EPSS 2.5%9.8CVE-2017-3181Tibco spotfire analyst sql injection vulnerabilityMultiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input bef…EPSS 1.7%9.8CVE-2018-5435Tibco spotfire analyst vulnerabilityThe TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics P…EPSS 3.2%9.4CVE-2025-3115Tibco spotfire enterprise runtime for r code injection vulnerabilityInjection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, …EPSS 0.68%8.8CVE-2019-8992Tibco activematrix bpm unrestricted file upload vulnerabilityThe administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIB…EPSS 2.1%8.8CVE-2019-8991Tibco activematrix bpm cross-site scripting vulnerabilityThe administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO A…EPSS 0.95%8.8CVE-2018-5437Tibco spotfire analyst vulnerabilityThe TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics P…EPSS 0.93%8.0CVE-2019-17334Tibco spotfire analyst incorrect default permissions vulnerabilityThe Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire D…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2014-7195), CISA KEV, FIRST EPSS (scores of 2026-10-10). This page is refreshed as NVD updates the record.