Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue affects Spotfire Enterprise Runtime for R - Server Edition: from 1.12.7 through 1.20.0; Spotfire Statistics Services: from 12.0.7 through 12.3.1, from 14.0.0 through 14.3.0; Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0.0 through 14.3.0; Spotfire Desktop: from 14.0 through 14.3.0; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0.0 through 14.3.0.
Fixes

Solution

* Spotfire Enterprise Runtime for R (aka TERR) 4.5.0, 5.0.0, 5.1.0, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 6.1.1, 6.1.2: upgrade to version 6.1.3 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.12.7 and earlier: upgrade to version 1.12.8 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.13.0, 1.14.0, 1.15.0, 1.16.0, 1.17.0, 1.17.1, 1.17.2, 1.17.3: upgrade to version 1.17.4 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.18.0, 1.19.0, 1.20.0: upgrade to version 1.21.0 or higher * Spotfire Statistics Services 12.0.7 and earlier: upgrade to version 12.0.8 or higher * Spotfire Statistics Services 12.1.0, 12.2.0, 12.3.0, 12.3.1, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Statistics Services 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher * Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher * Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire Desktop 14.3.0 and earlier: upgrade to version 14.4.0 or higher * Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11 or higher * Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Server 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher


Workaround

No workaround given by the vendor.

History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-10-29T19:56:28.829Z

Reserved: 2024-04-04T17:01:59.760Z

Link: CVE-2024-3331

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:08.452Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-27T19:15:15.153

Modified: 2024-11-21T09:29:24.200

Link: CVE-2024-3331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.