CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-3115

CVSS 9.4v4.0pub. 2025-04-09upd. 2025-11-11

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

🤖 AI Analysis
How it works

An attacker with authenticated access (low privileges) can inject malicious code into functions executed by the platform (CWE-94 — code injection). At the same time, insufficient validation of file names during upload allows uploading a file with a crafted name, which can then be executed by the server. Both vectors lead to arbitrary code execution on the server side.

Impact

An attacker can gain full control over the system executing vulnerable functions, including server data and resources. If the attack is successful, it is also possible to compromise the confidentiality, integrity, and availability of related systems (high impact on external systems according to CVSS vector).

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references — detailed information about affected and patched versions is available in the official Tibco Spotfire security bulletin dated 2025-04-08: https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3115-r3485/

Who is affected

Tibco Spotfire Analytics Platform, Tibco Spotfire Analyst, Tibco Spotfire Desktop, Tibco Spotfire Deployment Kit, Tibco Spotfire Statistics Services — specific versions indicated in the manufacturer's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tibco Spotfire Analyst

    APP
    Tibco
    14.1.014.2.014.3.014.4.014.4.1< 14.0.6
  • Tibco Spotfire Analytics Platform

    APP
    Tibco
    < 14.4.2
  • Tibco Spotfire Deployment Kit

    APP
    Tibco
    14.1.014.2.014.3.014.4.014.4.1< 14.0.7
  • Tibco Spotfire Desktop

    APP
    Tibco
    < 14.4.2
  • Tibco Spotfire Enterprise Runtime For R

    APP
    Tibco
    1.18.01.19.01.20.01.21.01.21.1< 1.17.7< 6.1.5
  • Tibco Spotfire Statistics Services

    APP
    Tibco
    14.1.014.2.014.3.014.4.014.4.1< 14.0.7
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-29268CRITICAL9.8PL ✓same product

Nieuwierzytelniony upload/modyfikacja plików w TIBCO Spotfire Statistics Services

CVE-2022-41558CRITICAL9.0PL ✓same product

Stored XSS w komponencie Visualizations TIBCO Spotfire

CVE-2018-12410CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w TIBCO Spotfire Statistics Services

CVE-2017-3181CRITICAL9.8PL ✓same product

SQL Injection w wielu produktach TIBCO Spotfire (CVE-2017-3181)

CVE-2018-5435CRITICAL9.6PL ✓same product

RCE w komponentach klienckich TIBCO Spotfire