CVE-2024-3331: Spotfire: NTLM token leakage
Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue affects Spotfire Enterprise Runtime for R - Server Edition: from 1.12.7 through 1.20.0; Spotfire Statistics Services: from 12.0.7 through 12.3.1, from 14.0.0 through 14.3.0; Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0.0 through 14.3.0; Spotfire Desktop: from 14.0 through 14.3.0; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0.0 through 14.3.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3331?
The severity of CVE-2024-3331 depends on the privileges of the user running the affected software.
How do I fix CVE-2024-3331?
To fix CVE-2024-3331, upgrade to the latest version of the TIBCO Spotfire software that addresses this vulnerability.
What products are affected by CVE-2024-3331?
CVE-2024-3331 affects TIBCO Spotfire Enterprise Runtime for R - Server Edition, Statistics Services, Analyst, Desktop, and Server.
What versions are vulnerable to CVE-2024-3331?
Versions of the affected TIBCO Spotfire products between specified ranges are vulnerable to CVE-2024-3331.
What type of vulnerability is CVE-2024-3331?
CVE-2024-3331 is a user privilege escalation vulnerability in several TIBCO Spotfire products.