CVE-2025-3114: Spotfire Deployment Kit Used In Spotfire Server
Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security validation, potentially leading to system compromise. Sandbox Bypass Vulnerability: A flaw in the TERR security mechanism allows attackers to bypass sandbox restrictions, enabling the execution of untrusted code without appropriate controls.
Affected products
- Spotfire Deployment Kit Used In Spotfire Server: from 14, up to and including 0.6; version 14.1.0 only; version 14.2.0 only; version 14.3.0 only; version 14.4.0 only; version 14.4.1 only
- Spotfire Spotfire Analyst: from 14, up to and including 0.5; version 14.1.0 only; version 14.2.0 only; version 14.3.0 only; version 14.4.0 only; version 14.4.1 only
- Spotfire Spotfire Desktop: from 14, up to and including 4.1
- Spotfire Spotfire Enterprise Runtime For R: from 6, up to and including 1.4
- Spotfire Spotfire Enterprise Runtime For R - Server Edition: from 1, up to and including 17.6; version 1.18.0 only; version 1.19.0 only; version 1.20.0 only; version 1.21.0 only; version 1.21.1 only
- Spotfire Spotfire For Aws Marketplace
- Spotfire Spotfire Statistics Services: from 14, up to and including 0.6; version 14.1.0 only; version 14.2.0 only; version 14.3.0 only; version 14.4.0 only; version 14.4.1 only
Published 2025-04-09. Last modified 2026-06-17.