CVE-2025-3115

CRITICAL EPSS 41.9%
Published Apr 9, 20251y ago · Modified Jun 17, 20261w ago
9.4 CVSS 4.0
Critical
Find Similar
Published Apr 9, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

CVSS Details

Base Score
9.4
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
41.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-94 Improper Control of Generation of Code (Code Injection) Injection

Affected Products 27

VendorProductVersionRange
tibcospotfire_enterprise_runtime_for_r* <6.1.5
tibcospotfire_statistics_services* <14.0.7
tibcospotfire_statistics_services14.1.0any
tibcospotfire_statistics_services14.2.0any
tibcospotfire_statistics_services14.3.0any
tibcospotfire_statistics_services14.4.0any
tibcospotfire_statistics_services14.4.1any
tibcospotfire_enterprise_runtime_for_r* <1.17.7
tibcospotfire_enterprise_runtime_for_r1.18.0any
tibcospotfire_enterprise_runtime_for_r1.19.0any
tibcospotfire_enterprise_runtime_for_r1.20.0any
tibcospotfire_enterprise_runtime_for_r1.21.0any
tibcospotfire_enterprise_runtime_for_r1.21.1any
tibcospotfire_analyst* <14.0.6
tibcospotfire_analyst14.1.0any
tibcospotfire_analyst14.2.0any
tibcospotfire_analyst14.3.0any
tibcospotfire_analyst14.4.0any
tibcospotfire_analyst14.4.1any
tibcospotfire_deployment_kit* <14.0.7
tibcospotfire_deployment_kit14.1.0any
tibcospotfire_deployment_kit14.2.0any
tibcospotfire_deployment_kit14.3.0any
tibcospotfire_deployment_kit14.4.0any
tibcospotfire_deployment_kit14.4.1any
tibcospotfire_desktop* <14.4.2
tibcospotfire_analytics_platform* <14.4.2

References 1

  • community.spotfire.com https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3115-r3485/

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.