← Back

CVE-2025-3115

nvd nist
Published: Apr 9, 2025Modified: Nov 11, 2025

JSON object

Loading...
9.4
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@tibco.com (Secondary)

Description

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

Affected (27)

6 products
Spotfire Enterprise Runtime For R
Spotfire Statistics Services
Spotfire Analyst
Spotfire Deployment Kit
Spotfire Desktop
Spotfire Analytics Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.1.5
Configuration B
6 vulnerable
Configuration C
6 vulnerable
Configuration D
6 vulnerable
Vulnerable SoftwareAffected Versions
Tibco
Before 14.0.6
Version 14.1.0
Version 14.2.0
Version 14.3.0
Version 14.4.0
Version 14.4.1
Configuration E
6 vulnerable
Vulnerable SoftwareAffected Versions
Tibco
Before 14.0.7
Version 14.1.0
Version 14.2.0
Version 14.3.0
Version 14.4.0
Version 14.4.1
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 14.4.2
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 14.4.2

Timeline

No history available yet.