CVE-2025-3114 Details
Description
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security validation, potentially leading to system compromise. Sandbox Bypass Vulnerability: A flaw in the TERR security mechanism allows attackers to bypass sandbox restrictions, enabling the execution of untrusted code without appropriate controls.
A code execution vulnerability has been identified in TIBCO Spotfire products, allowing attackers to execute arbitrary code by creating specially crafted files that bypass security validations. This vulnerability also includes a sandbox bypass, enabling the execution of untrusted code without proper controls. Affected products include Spotfire Enterprise Runtime for R, Spotfire Statistics Services, Spotfire Analyst, Spotfire Desktop, and the Deployment Kit used in Spotfire Server. The vulnerability is present in several different versions and ranges, with specific upgrade paths available for each product.
Users are advised to upgrade to the latest versions of the affected Spotfire products. Specific upgrade instructions can be found in the Spotfire Security Advisory published on April 08, 2025.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 9, 2025CISA-ADP
Assessed Apr 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | CISA-ADP |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| TIBCO Spotfire | All versions |
CPE
Remediation
| |
| TIBCO Spotfire Enterprise Runtime for R | All versions |
CPE
Remediation
| |
| TIBCO Spotfire Statistics Services | All versions |
CPE
Remediation
| |
| TIBCO Spotfire Enterprise Runtime for R - Server Edition | All versions |
CPE
Remediation
| |
| TIBCO Spotfire Analyst | All versions |
CPE
Remediation
| |
| TIBCO Spotfire Deployment Kit | All versions |
CPE
Remediation
| |
| TIBCO Spotfire Desktop | <= 14.4.1 (semver) |
CPE
Remediation
| |
| TIBCO Spotfire for AWS Marketplace | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | CVE Modified | CISA-ADP |
| Apr 9, 2025 | New CVE Received | [email protected] |
Volerion