Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
An attacker with authenticated access (low privileges) can inject malicious code into functions executed by the platform (CWE-94 — code injection). At the same time, insufficient validation of file names during upload allows uploading a file with a crafted name, which can then be executed by the server. Both vectors lead to arbitrary code execution on the server side.
An attacker can gain full control over the system executing vulnerable functions, including server data and resources. If the attack is successful, it is also possible to compromise the confidentiality, integrity, and availability of related systems (high impact on external systems according to CVSS vector).
Patches available from the manufacturer should be applied in accordance with the references — detailed information about affected and patched versions is available in the official Tibco Spotfire security bulletin dated 2025-04-08: https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3115-r3485/
Tibco Spotfire Analytics Platform, Tibco Spotfire Analyst, Tibco Spotfire Desktop, Tibco Spotfire Deployment Kit, Tibco Spotfire Statistics Services — specific versions indicated in the manufacturer's references.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTibco Spotfire Analyst
APPTibco14.1.014.2.014.3.014.4.014.4.1< 14.0.6Tibco Spotfire Analytics Platform
APPTibco< 14.4.2Tibco Spotfire Deployment Kit
APPTibco14.1.014.2.014.3.014.4.014.4.1< 14.0.7Tibco Spotfire Desktop
APPTibco< 14.4.2Tibco Spotfire Enterprise Runtime For R
APPTibco1.18.01.19.01.20.01.21.01.21.1< 1.17.7< 6.1.5Tibco Spotfire Statistics Services
APPTibco14.1.014.2.014.3.014.4.014.4.1< 14.0.7
Related vulnerabilities
Nieuwierzytelniony upload/modyfikacja plików w TIBCO Spotfire Statistics Services
Stored XSS w komponencie Visualizations TIBCO Spotfire
RCE bez uwierzytelnienia w TIBCO Spotfire Statistics Services
SQL Injection w wielu produktach TIBCO Spotfire (CVE-2017-3181)
RCE w komponentach klienckich TIBCO Spotfire