Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3115


Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution


Published

2025-04-09T18:15:50.813

Last Modified

2025-04-22T16:46:51.650

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tibco spotfire_enterprise_runtime_for_r < 6.1.5 Yes
Application tibco spotfire_statistics_services < 14.0.7 Yes
Application tibco spotfire_statistics_services 14.1.0 Yes
Application tibco spotfire_statistics_services 14.2.0 Yes
Application tibco spotfire_statistics_services 14.3.0 Yes
Application tibco spotfire_statistics_services 14.4.0 Yes
Application tibco spotfire_statistics_services 14.4.1 Yes
Application tibco spotfire_enterprise_runtime_for_r < 1.17.7 Yes
Application tibco spotfire_enterprise_runtime_for_r 1.18.0 Yes
Application tibco spotfire_enterprise_runtime_for_r 1.19.0 Yes
Application tibco spotfire_enterprise_runtime_for_r 1.20.0 Yes
Application tibco spotfire_enterprise_runtime_for_r 1.21.0 Yes
Application tibco spotfire_enterprise_runtime_for_r 1.21.1 Yes
Application tibco spotfire_analyst < 14.0.6 Yes
Application tibco spotfire_analyst 14.1.0 Yes
Application tibco spotfire_analyst 14.2.0 Yes
Application tibco spotfire_analyst 14.3.0 Yes
Application tibco spotfire_analyst 14.4.0 Yes
Application tibco spotfire_analyst 14.4.1 Yes
Application tibco spotfire_deployment_kit < 14.0.7 Yes
Application tibco spotfire_deployment_kit 14.1.0 Yes
Application tibco spotfire_deployment_kit 14.2.0 Yes
Application tibco spotfire_deployment_kit 14.3.0 Yes
Application tibco spotfire_deployment_kit 14.4.0 Yes
Application tibco spotfire_deployment_kit 14.4.1 Yes
Application tibco spotfire_desktop < 14.4.2 Yes
Application tibco spotfire_analytics_platform < 14.4.2 Yes

References