Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.
Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
References
Link | Resource |
---|---|
https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
22 Apr 2025, 16:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484/ - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
|
CPE | cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.20.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.18.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_analytics_platform:*:*:*:*:*:aws_marketplace:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.3.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.3.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.4.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.1:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.4.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.4.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.19.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.4.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.1.0:*:*:*:*:*:*:* |
|
First Time |
Tibco spotfire Deployment Kit
Tibco spotfire Statistics Services Tibco spotfire Analytics Platform Tibco Tibco spotfire Enterprise Runtime For R Tibco spotfire Analyst Tibco spotfire Desktop |
09 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 |
09 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-09 18:15
Updated : 2025-04-22 16:46
NVD link : CVE-2025-3115
Mitre link : CVE-2025-3115
CVE.ORG link : CVE-2025-3115
JSON object : View
Products Affected
tibco
- spotfire_deployment_kit
- spotfire_analyst
- spotfire_desktop
- spotfire_statistics_services
- spotfire_enterprise_runtime_for_r
- spotfire_analytics_platform
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')