CVE-2024-3330: Spotfire Remote Code Execution Vulnerability
Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3330?
CVE-2024-3330 has been classified as a high-severity vulnerability due to its potential for arbitrary code execution.
Which versions are affected by CVE-2024-3330?
CVE-2024-3330 affects Spotfire Spotfire Analyst versions from 12.0.9 to 12.5.0 and 14.0 to 14.0.2, Spotfire Spotfire Server from 12.0.10 to 12.5.0, 14.0 to 14.0.3, and 14.2.0 to 14.3.0, as well as Spotfire Spotfire for AWS Marketplace up to private version 14.3.0.
How do I fix CVE-2024-3330?
To mitigate CVE-2024-3330, users should upgrade to the latest versions of Spotfire Analyst, Server, or the AWS Marketplace edition as recommended in the security advisory.
How can attackers exploit CVE-2024-3330?
Attackers can exploit CVE-2024-3330 by convincing victims to open a malicious file, which may lead to arbitrary code execution on their system.
What are the potential impacts of CVE-2024-3330?
The potential impacts of CVE-2024-3330 include unauthorized access and control over the affected systems, leading to data breaches or further compromise.