CVE-2024-3331
Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue affects Spotfire Enterprise Runtime for R - Server Edition: from 1.12.7 through 1.20.0; Spotfire Statistics Services: from 12.0.7 through 12.3.1, from 14.0.0 through 14.3.0; Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0.0 through 14.3.0; Spotfire Desktop: from 14.0 through 14.3.0; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0.0 through 14.3.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3331",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3331",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-07-01T19:50:43.928829Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@tibco.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security@tibco.com",
"affectedData": [
{
"vendor": "Spotfire",
"product": "Spotfire Enterprise Runtime for R - Server Edition",
"versions": [
{
"status": "affected",
"version": "1.12.7",
"versionType": "patch",
"lessThanOrEqual": "1.20.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Spotfire",
"product": "Spotfire Statistics Services",
"versions": [
{
"status": "affected",
"version": "12.0.7",
"versionType": "patch",
"lessThanOrEqual": "12.3.1"
},
{
"status": "affected",
"version": "14.0.0",
"versionType": "patch",
"lessThanOrEqual": "14.3.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Spotfire",
"product": "Spotfire Analyst",
"versions": [
{
"status": "affected",
"version": "12.0.9",
"versionType": "patch",
"lessThanOrEqual": "12.5.0"
},
{
"status": "affected",
"version": "14.0.0",
"versionType": "Patch",
"lessThanOrEqual": "14.3.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Spotfire",
"product": "Spotfire Desktop",
"versions": [
{
"status": "affected",
"version": "14.0",
"versionType": "patch",
"lessThanOrEqual": "14.3.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Spotfire",
"product": "Spotfire Server",
"versions": [
{
"status": "affected",
"version": "12.0.10",
"versionType": "patch",
"lessThanOrEqual": "12.5.0"
},
{
"status": "affected",
"version": "14.0.0",
"versionType": "patch",
"lessThanOrEqual": "14.3.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-06-27T19:15:15.153",
"references": [
{
"url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3331-r3436/",
"source": "security@tibco.com"
},
{
"url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3331-r3436/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue affects Spotfire Enterprise Runtime for R - Server Edition: from 1.12.7 through 1.20.0; Spotfire Statistics Services: from 12.0.7 through 12.3.1, from 14.0.0 through 14.3.0; Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0.0 through 14.3.0; Spotfire Desktop: from 14.0 through 14.3.0; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0.0 through 14.3.0."
},
{
"lang": "es",
"value": "Vulnerabilidad en Spotfire Spotfire Enterprise Runtime para R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server permite El impacto de esta vulnerabilidad depende de los privilegios del usuario que ejecuta el software afectado. Este problema afecta Spotfire Enterprise Runtime para R - Server Edition: desde 1.12.7 hasta 1.20.0; Servicios de estadísticas de Spotfire: de 12.0.7 a 12.3.1, de 14.0.0 a 14.3.0; Spotfire Analyst: del 12.0.9 al 12.5.0, del 14.0.0 al 14.3.0; Spotfire Desktop: de 14.0 a 14.3.0; Servidor Spotfire: desde 12.0.10 hasta 12.5.0, desde 14.0.0 hasta 14.3.0."
}
],
"lastModified": "2026-06-17T07:43:47.553",
"sourceIdentifier": "security@tibco.com"
}