← All CVEs

CVE-2025-3115

critical · 9.4

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

9.4
CVSS
0.7%
EPSS (exploit prob.)
51st
EPSS percentile
2025-04-09
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
tibcospotfire_enterprise_runtime_for_r< 6.1.5
tibcospotfire_statistics_services< 14.0.7
tibcospotfire_statistics_services14.1.0
tibcospotfire_statistics_services14.2.0
tibcospotfire_statistics_services14.3.0
tibcospotfire_statistics_services14.4.0
tibcospotfire_statistics_services14.4.1
tibcospotfire_enterprise_runtime_for_r< 1.17.7
tibcospotfire_enterprise_runtime_for_r1.18.0
tibcospotfire_enterprise_runtime_for_r1.19.0
tibcospotfire_enterprise_runtime_for_r1.20.0
tibcospotfire_enterprise_runtime_for_r1.21.0
tibcospotfire_enterprise_runtime_for_r1.21.1
tibcospotfire_analyst< 14.0.6
tibcospotfire_analyst14.1.0
tibcospotfire_analyst14.2.0
tibcospotfire_analyst14.3.0
tibcospotfire_analyst14.4.0
tibcospotfire_analyst14.4.1
tibcospotfire_deployment_kit< 14.0.7
tibcospotfire_deployment_kit14.1.0
tibcospotfire_deployment_kit14.2.0
tibcospotfire_deployment_kit14.3.0
tibcospotfire_deployment_kit14.4.0
tibcospotfire_deployment_kit14.4.1
tibcospotfire_desktop< 14.4.2
tibcospotfire_analytics_platform< 14.4.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-3115