CVE-2025-3115: TIBCO Spotfire Analyst

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution

Affected products

  • TIBCO Spotfire Analyst: before 14.0.6 (fixed in 14.0.6); version 14.1.0 only; version 14.2.0 only; version 14.3.0 only; version 14.4.0 only; version 14.4.1 only
  • TIBCO Spotfire Analytics Platform: before 14.4.2 (fixed in 14.4.2)
  • TIBCO Spotfire Deployment Kit: before 14.0.7 (fixed in 14.0.7); version 14.1.0 only; version 14.2.0 only; version 14.3.0 only; version 14.4.0 only; version 14.4.1 only
  • TIBCO Spotfire Desktop: before 14.4.2 (fixed in 14.4.2)
  • TIBCO Spotfire Enterprise Runtime For R: before 6.1.5 (fixed in 6.1.5); before 1.17.7 (fixed in 1.17.7); version 1.18.0 only; version 1.19.0 only; version 1.20.0 only; version 1.21.0 only; …
  • TIBCO Spotfire Statistics Services: before 14.0.7 (fixed in 14.0.7); version 14.1.0 only; version 14.2.0 only; version 14.3.0 only; version 14.4.0 only; version 14.4.1 only

Published 2025-04-09. Last modified 2026-06-17.