CVE-2025-3115
Spotfire Data Function Vulnerability
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.4EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
09 abr 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.
Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Productos afectados
Spotfire · Deployment Kit used in Spotfire ServerSpotfire · Spotfire AnalystSpotfire · Spotfire DesktopSpotfire · Spotfire Enterprise Runtime for R - Server EditionSpotfire · Spotfire for AWS MarketplaceSpotfire · Spotfire Service for PythonSpotfire · Spotfire Service for RSpotfire · Spotfire Statistics Services¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →