CVE-2025-3115
9.4
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@tibco.com (Secondary)
Description
Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.
Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
Affected (27)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.1.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 14.0.7 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.17.7 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 14.0.6 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 14.0.7 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 14.4.2 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 14.4.2 |
References (1)
Timeline
No history available yet.