CVE-2025-3115

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
09/04/2025
Last modified:
11/11/2025

Description

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.<br /> Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:* 6.1.5 (excluding)
cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:* 14.0.7 (excluding)
cpe:2.3:a:tibco:spotfire_statistics_services:14.1.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.2.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_statistics_services:14.4.1:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:server:*:*:* 1.17.7 (excluding)
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.18.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.19.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.20.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.0:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.1:*:*:*:server:*:*:*
cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:* 14.0.6 (excluding)
cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*