CVE-2025-3115

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
Configurations

Configuration 1 (hide)

cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.1.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.2.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.4.1:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.18.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.19.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.20.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.1:*:*:*:server:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_analyst:14.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_analyst:14.4.1:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:tibco:spotfire_deployment_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_deployment_kit:14.1.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_deployment_kit:14.2.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_deployment_kit:14.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.1:*:*:*:*:*:*:*

Configuration 6 (hide)

cpe:2.3:a:tibco:spotfire_desktop:*:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:a:tibco:spotfire_analytics_platform:*:*:*:*:*:aws_marketplace:*:*

History

No history.

Information

Published : 2025-04-09 18:15

Updated : 2025-11-11 12:15


NVD link : CVE-2025-3115

Mitre link : CVE-2025-3115

CVE.ORG link : CVE-2025-3115


JSON object : View

Products Affected

tibco

  • spotfire_deployment_kit
  • spotfire_desktop
  • spotfire_enterprise_runtime_for_r
  • spotfire_analyst
  • spotfire_analytics_platform
  • spotfire_statistics_services
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')