VYPR
Critical severity9.8NVD Advisory· Published Apr 9, 2025· Updated Jun 17, 2026

CVE-2025-3115

CVE-2025-3115

Description

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

Affected products

30
  • cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*range: <14.0.6
    • cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_analyst:14.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_analyst:14.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:spotfire_analytics_platform:*:*:*:*:*:aws_marketplace:*:*
    Range: <14.4.2
  • cpe:2.3:a:tibco:spotfire_deployment_kit:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:tibco:spotfire_deployment_kit:*:*:*:*:*:*:*:*range: <14.0.7
    • cpe:2.3:a:tibco:spotfire_deployment_kit:14.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_deployment_kit:14.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_deployment_kit:14.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:spotfire_desktop:*:*:*:*:*:*:*:*
    Range: <14.4.2
  • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:*+ 6 more
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:*range: <6.1.5
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:server:*:*:*range: <1.17.7
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.18.0:*:*:*:server:*:*:*
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.19.0:*:*:*:server:*:*:*
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.20.0:*:*:*:server:*:*:*
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.0:*:*:*:server:*:*:*
    • cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.1:*:*:*:server:*:*:*
  • cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:*range: <14.0.7
    • cpe:2.3:a:tibco:spotfire_statistics_services:14.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_statistics_services:14.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_statistics_services:14.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_statistics_services:14.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tibco:spotfire_statistics_services:14.4.1:*:*:*:*:*:*:*
  • Range: 14.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.