CVE Database
/

CVE-2025-3115

Back to search

CVE-2025-3115

Published: Apr 9, 2025

Modified: Nov 11, 2025

PUBLISHED

Description

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

VendorProductVersions

Spotfire

Spotfire Statistics Services

affected
14 - < 14.0.7
affected
14.1.0
affected
14.2.0
affected
14.3.0
affected
14.4.0

+1 more versions

Spotfire

Spotfire Analyst

affected
14.0 - < 14.0.6
affected
14.1.0
affected
14.2.0
affected
14.3.0
affected
14.4.0

+1 more versions

Spotfire

Deployment Kit used in Spotfire Server

affected
14.0 - < 14.0.7
affected
14.1.0
affected
14.2.0
affected
14.3.0
affected
14.4.0

+1 more versions

Spotfire

Spotfire Desktop

affected
14.4 - < 14.4.2

Spotfire

Spotfire for AWS Marketplace

unknown
14.4 - < 14.4.2

Spotfire

Spotfire Enterprise Runtime for R - Server Edition

affected
1.17 - < 1.17.7
affected
1.18.0
affected
1.19.0
affected
1.20.0
affected
1.21.0

+1 more versions

Spotfire

Spotfire Service for Python

affected
1.17 - < 1.17.7
affected
1.18.0 - <= 1.21.1

Spotfire

Spotfire Service for R

affected
1.17 - < 1.17.7
affected
1.18.0 - <= 1.21.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now