CVE-2025-3115
critical · 9.4Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
9.4
CVSS
0.7%
EPSS (exploit prob.)
51st
EPSS percentile
2025-04-09
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tibco | spotfire_enterprise_runtime_for_r | < 6.1.5 |
| tibco | spotfire_statistics_services | < 14.0.7 |
| tibco | spotfire_statistics_services | 14.1.0 |
| tibco | spotfire_statistics_services | 14.2.0 |
| tibco | spotfire_statistics_services | 14.3.0 |
| tibco | spotfire_statistics_services | 14.4.0 |
| tibco | spotfire_statistics_services | 14.4.1 |
| tibco | spotfire_enterprise_runtime_for_r | < 1.17.7 |
| tibco | spotfire_enterprise_runtime_for_r | 1.18.0 |
| tibco | spotfire_enterprise_runtime_for_r | 1.19.0 |
| tibco | spotfire_enterprise_runtime_for_r | 1.20.0 |
| tibco | spotfire_enterprise_runtime_for_r | 1.21.0 |
| tibco | spotfire_enterprise_runtime_for_r | 1.21.1 |
| tibco | spotfire_analyst | < 14.0.6 |
| tibco | spotfire_analyst | 14.1.0 |
| tibco | spotfire_analyst | 14.2.0 |
| tibco | spotfire_analyst | 14.3.0 |
| tibco | spotfire_analyst | 14.4.0 |
| tibco | spotfire_analyst | 14.4.1 |
| tibco | spotfire_deployment_kit | < 14.0.7 |
| tibco | spotfire_deployment_kit | 14.1.0 |
| tibco | spotfire_deployment_kit | 14.2.0 |
| tibco | spotfire_deployment_kit | 14.3.0 |
| tibco | spotfire_deployment_kit | 14.4.0 |
| tibco | spotfire_deployment_kit | 14.4.1 |
| tibco | spotfire_desktop | < 14.4.2 |
| tibco | spotfire_analytics_platform | < 14.4.2 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-3115