TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Execution
Published Sep 18, 2019
9.9
CRITICALCVSS 3.1
EPSS 3.72%
Description
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.
Affected products
-
- Version 1.2.0 and belowStatusaffectedConstraints-
- Version
- Vendor TIBCO Software Inc. Product TIBCO Spotfire Analytics Platform for AWS Marketplace Defaultn/a
- Version 10.4.0StatusaffectedConstraints-
- Version 10.5.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TIBCO Software Inc. | TIBCO Enterprise Runtime for R - Server Edition | n/a |
| |||||||||
| TIBCO Software Inc. | TIBCO Spotfire Analytics Platform for AWS Marketplace | n/a |
|
- ≤ 1.2.0
- 10.4.0
- 10.5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
TIBCO has released updated versions of the affected systems which address this issue:
TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below update to version 1.2.1 or higher TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0 update to version 10.5.1 or higher.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 3.72% (0.03723) | 89.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.72% (0.03723) | 88.34th | v5 (v2026.06.15) |
| Mar 30, 2025 | 3.13% (0.03134) | 85.69th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.20% (0.08196) | 86.74th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.94% (0.02939) | 85.52th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.55% (0.00547) | 77.67th | v3 (v2023.03.01) |
| Feb 29, 2024 | 0.55% (0.00547) | 76.87th | v3 (v2023.03.01) |
| Oct 28, 2023 | 0.55% (0.00547) | 74.87th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.40% (0.00404) | 70.11th | v3 (v2023.03.01) |
| Jun 5, 2023 | 0.36% (0.00355) | 67.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.37% (0.00370) | 68.27th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.98% (0.01978) | 79.27th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.98% (0.01978) | 77.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.85% (0.23850) | 95.09th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.88% (0.05885) | 81.24th | v1 |
| Jan 6, 2022 | 5.88% (0.05885) | 81.05th | v1 |
| Sep 1, 2021 | 1.37% (0.01374) | 70.79th | v1 |
| Apr 14, 2021 | 1.37% (0.01374) | 0.00th | v1 |
No CWE recorded.
References (2)
- http://www.tibco.com/services/support/advisories x_refsource_MISCVendor Advisory
- https://www.tibco.com/support/advisories/2019/09/tibco-security-advisory-september-17-2019-tibco-enterprise-runtime-for-r-server-2019-11211 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.tibco.com/services/support/advisories | x_refsource_MISCVendor Advisory | |
| https://www.tibco.com/support/advisories/2019/09/tibco-security-advisory-september-17-2019-tibco-enterprise-runtime-for-r-server-2019-11211 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.