CVE-2025-3115

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.
Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
tibcoCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
tibcospotfire_enterprise_runtime_for_r
𝑥
< 6.1.5
tibcospotfire_statistics_services
𝑥
< 14.0.7
tibcospotfire_statistics_services
14.1.0
tibcospotfire_statistics_services
14.2.0
tibcospotfire_statistics_services
14.3.0
tibcospotfire_statistics_services
14.4.0
tibcospotfire_statistics_services
14.4.1
tibcospotfire_enterprise_runtime_for_r
𝑥
< 1.17.7
tibcospotfire_enterprise_runtime_for_r
1.18.0
tibcospotfire_enterprise_runtime_for_r
1.19.0
tibcospotfire_enterprise_runtime_for_r
1.20.0
tibcospotfire_enterprise_runtime_for_r
1.21.0
tibcospotfire_enterprise_runtime_for_r
1.21.1
tibcospotfire_analyst
𝑥
< 14.0.6
tibcospotfire_analyst
14.1.0
tibcospotfire_analyst
14.2.0
tibcospotfire_analyst
14.3.0
tibcospotfire_analyst
14.4.0
tibcospotfire_analyst
14.4.1
tibcospotfire_deployment_kit
𝑥
< 14.0.7
tibcospotfire_deployment_kit
14.1.0
tibcospotfire_deployment_kit
14.2.0
tibcospotfire_deployment_kit
14.3.0
tibcospotfire_deployment_kit
14.4.0
tibcospotfire_deployment_kit
14.4.1
tibcospotfire_desktop
𝑥
< 14.4.2
tibcospotfire_analytics_platform
𝑥
< 14.4.2
𝑥
= Vulnerable software versions