CVE-2025-3115
Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation65 %
AV:N con PR:L indica acceso remoto autenticado a servicio TIBCO; CWE-94 (code injection) y descripción de inyección/ejecución maliciosa sustentan T1059; escalada a root/admin probable en entorno empresarial (VI:H, VA:H).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (6)
CWE
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-3115",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-3115",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-09T18:28:35.698097Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security@tibco.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.4,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security@tibco.com",
"affectedData": [
{
"vendor": "Spotfire",
"product": "Spotfire Statistics Services",
"versions": [
{
"status": "affected",
"version": "14",
"lessThan": "14.0.7",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.1.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.2.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.3.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.4.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.4.1",
"versionType": "Patch"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Spotfire",
"product": "Spotfire Analyst",
"versions": [
{
"status": "affected",
"version": "14.0",
"lessThan": "14.0.6",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.1.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.2.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.3.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.4.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.4.1",
"versionType": "Patch"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Spotfire",
"product": "Deployment Kit used in Spotfire Server",
"versions": [
{
"status": "affected",
"version": "14.0",
"lessThan": "14.0.7",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.1.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.2.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.3.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.4.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "14.4.1",
"versionType": "Patch"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Spotfire",
"product": "Spotfire Desktop",
"versions": [
{
"status": "affected",
"version": "14.4",
"lessThan": "14.4.2",
"versionType": "Patch"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Spotfire",
"product": "Spotfire for AWS Marketplace",
"versions": [
{
"status": "unknown",
"version": "14.4",
"lessThan": "14.4.2",
"versionType": "Patch"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Spotfire",
"product": "Spotfire Enterprise Runtime for R - Server Edition",
"versions": [
{
"status": "affected",
"version": "1.17",
"lessThan": "1.17.7",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.18.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.19.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.20.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.21.0",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.21.1",
"versionType": "Patch"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Spotfire",
"product": "Spotfire Service for Python",
"versions": [
{
"status": "affected",
"version": "1.17",
"lessThan": "1.17.7",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.18.0",
"versionType": "Patch",
"lessThanOrEqual": "1.21.1"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Spotfire",
"product": "Spotfire Service for R",
"versions": [
{
"status": "affected",
"version": "1.17",
"lessThan": "1.17.7",
"versionType": "Patch"
},
{
"status": "affected",
"version": "1.18.0",
"versionType": "Patch",
"lessThanOrEqual": "1.21.1"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-04-09T18:15:50.813",
"references": [
{
"url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3115-r3485/",
"source": "security@tibco.com"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.\nAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution"
},
{
"lang": "es",
"value": "Vulnerabilidades de inyección: Los atacantes pueden inyectar código malicioso, lo que podría permitirle controlar el sistema que ejecuta estas funciones. Además, una validación insuficiente de los nombres de archivo durante la carga puede permitir que los atacantes carguen y ejecuten archivos maliciosos, lo que provoca la ejecución de código arbitrario."
}
],
"lastModified": "2026-06-17T09:19:12.623",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4B95026-0F1F-498E-A9F6-E6C8128C96D7",
"versionEndExcluding": "6.1.5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_statistics_services:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D32EAFEE-068C-411B-835A-3EB904EF1D72",
"versionEndExcluding": "14.0.7"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_statistics_services:14.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7C020EF-6D20-4898-B87C-947856FFA863"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_statistics_services:14.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1658C79B-930F-4810-AEA0-CA028AAF0C40"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_statistics_services:14.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9366B298-53DA-480A-8511-F26A5993BBB1"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_statistics_services:14.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24E86CD4-74B8-452C-AB07-1056D88EBA69"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_statistics_services:14.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1FE621F-3100-40F2-B5CA-586CC399BF0D"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:*:*:*:*:server:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFDC8DE8-CA02-403D-ACC9-AAFD83931EF4",
"versionEndExcluding": "1.17.7"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.18.0:*:*:*:server:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C8006F5-94D2-41AD-971E-3E4949AB3E85"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.19.0:*:*:*:server:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4F950F4-8EBB-49BF-A04F-1FC53ADF5B37"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.20.0:*:*:*:server:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DDF81DF-0B5D-47B0-95CA-99FE80193632"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.0:*:*:*:server:*:*:*",
"vulnerable": true,
"matchCriteriaId": "470B940C-EC98-48AC-A723-6E7358355A4C"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_enterprise_runtime_for_r:1.21.1:*:*:*:server:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE050D37-B646-4A65-A580-D2AEFB024216"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_analyst:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1159D5C-5687-4634-8372-2D78E3AC4EED",
"versionEndExcluding": "14.0.6"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_analyst:14.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB4B3273-A4D0-4455-9957-3FB21273E509"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_analyst:14.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "482923B8-BF2E-4EB1-A04A-BF139703DA49"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_analyst:14.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCF8F9F1-2DE8-4ABB-BC5E-C75D81ACA0B0"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_analyst:14.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "362FBA49-9BEA-4946-9F64-0E5FB57B8AC3"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_analyst:14.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EC54B56-2861-404F-91F5-2FC9C2B6F794"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_deployment_kit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E9B3AD9-1370-43F5-82FF-D62FE7EB14BB",
"versionEndExcluding": "14.0.7"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_deployment_kit:14.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB5F5802-BBC6-41E6-BB6A-FB58C0806C18"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_deployment_kit:14.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0760EB3A-55CD-4F7C-A60B-9A2B01A7D7AF"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_deployment_kit:14.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAFACCD8-2FD1-4759-93A4-91798A1D5E4B"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F60D8880-17CA-425D-B4A4-42F67DF59E67"
},
{
"criteria": "cpe:2.3:a:tibco:spotfire_deployment_kit:14.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0429550-AC79-489D-9D21-C2E0CF5F68DD"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_desktop:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20E73759-DAA6-4426-BCCC-3C430F24B58B",
"versionEndExcluding": "14.4.2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:spotfire_analytics_platform:*:*:*:*:*:aws_marketplace:*:*",
"vulnerable": true,
"matchCriteriaId": "3D1EB109-FC21-404F-8129-73A5363B5A94",
"versionEndExcluding": "14.4.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@tibco.com"
}