First published: Thu Jun 27 2024(Updated: )
Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire Analyst | >=12.0.9<12.5.0>=14.0<14.0.2 | |
TIBCO Spotfire | >=12.0.10<12.5.0>=14.0<14.0.3>=14.2.0<=14.3.0 | |
TIBCO Spotfire Analyst | <14.3.0 |
* Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher * Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher * Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 * Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11 * Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Server 14.2.0, 14.3.0: upgrade to version 14.4.0 * Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3330 has been classified as a high-severity vulnerability due to its potential for arbitrary code execution.
CVE-2024-3330 affects Spotfire Spotfire Analyst versions from 12.0.9 to 12.5.0 and 14.0 to 14.0.2, Spotfire Spotfire Server from 12.0.10 to 12.5.0, 14.0 to 14.0.3, and 14.2.0 to 14.3.0, as well as Spotfire Spotfire for AWS Marketplace up to private version 14.3.0.
To mitigate CVE-2024-3330, users should upgrade to the latest versions of Spotfire Analyst, Server, or the AWS Marketplace edition as recommended in the security advisory.
Attackers can exploit CVE-2024-3330 by convincing victims to open a malicious file, which may lead to arbitrary code execution on their system.
The potential impacts of CVE-2024-3330 include unauthorized access and control over the affected systems, leading to data breaches or further compromise.