Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.
Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
References
Link | Resource |
---|---|
https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
22 Apr 2025, 16:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484/ - Vendor Advisory | |
First Time |
Tibco spotfire Desktop
Tibco spotfire Analyst Tibco spotfire Enterprise Runtime For R Tibco spotfire Deployment Kit Tibco Tibco spotfire Analytics Platform Tibco spotfire Statistics Services |
|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:tibco:spotfire_statistics_services:14.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.4.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_desktop:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.4.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.19.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.3.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.3.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.1:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.4.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analytics_platform:*:*:*:*:*:aws_marketplace:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.4.1:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:14.1.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.20.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_deployment_kit:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_statistics_services:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.18.0:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:server:*:*:* cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:* |
09 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 |
09 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-09 18:15
Updated : 2025-04-22 16:46
NVD link : CVE-2025-3115
Mitre link : CVE-2025-3115
CVE.ORG link : CVE-2025-3115
JSON object : View
Products Affected
tibco
- spotfire_enterprise_runtime_for_r
- spotfire_statistics_services
- spotfire_desktop
- spotfire_deployment_kit
- spotfire_analyst
- spotfire_analytics_platform
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')