{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2024-3331",
        "ASSIGNER": "security@tibco.com",
        "STATE": "PUBLIC"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue affects Spotfire Enterprise Runtime for R - Server Edition: from 1.12.7 through 1.20.0; Spotfire Statistics Services: from 12.0.7 through 12.3.1, from 14.0.0 through 14.3.0; Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0.0 through 14.3.0; Spotfire Desktop: from 14.0 through 14.3.0; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0.0 through 14.3.0."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "n/a"
                    }
                ]
            }
        ]
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "vendor_name": "Spotfire",
                    "product": {
                        "product_data": [
                            {
                                "product_name": "Spotfire Enterprise Runtime for R - Server Edition",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "<=",
                                            "version_name": "1.12.7",
                                            "version_value": "1.20.0"
                                        }
                                    ]
                                }
                            },
                            {
                                "product_name": "Spotfire Statistics Services",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "<=",
                                            "version_name": "12.0.7",
                                            "version_value": "12.3.1"
                                        },
                                        {
                                            "version_affected": "<=",
                                            "version_name": "14.0.0",
                                            "version_value": "14.3.0"
                                        }
                                    ]
                                }
                            },
                            {
                                "product_name": "Spotfire Analyst",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "<=",
                                            "version_name": "12.0.9",
                                            "version_value": "12.5.0"
                                        },
                                        {
                                            "version_affected": "<=",
                                            "version_name": "14.0.0",
                                            "version_value": "14.3.0"
                                        }
                                    ]
                                }
                            },
                            {
                                "product_name": "Spotfire Desktop",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "<=",
                                            "version_name": "14.0",
                                            "version_value": "14.3.0"
                                        }
                                    ]
                                }
                            },
                            {
                                "product_name": "Spotfire Server",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "<=",
                                            "version_name": "12.0.10",
                                            "version_value": "12.5.0"
                                        },
                                        {
                                            "version_affected": "<=",
                                            "version_name": "14.0.0",
                                            "version_value": "14.3.0"
                                        }
                                    ]
                                }
                            }
                        ]
                    }
                }
            ]
        }
    },
    "references": {
        "reference_data": [
            {
                "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3331-r3436/",
                "refsource": "MISC",
                "name": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3331-r3436/"
            }
        ]
    },
    "generator": {
        "engine": "Vulnogram 0.2.0"
    },
    "source": {
        "discovery": "UNKNOWN"
    },
    "solution": [
        {
            "lang": "en",
            "supportingMedia": [
                {
                    "base64": false,
                    "type": "text/html",
                    "value": "<b><div><b><ul><li><p><span style=\"background-color: transparent;\">Spotfire Enterprise Runtime for R (aka TERR) 4.5.0, 5.0.0, 5.1.0, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 6.1.1, 6.1.2: upgrade to version 6.1.3 or higher</span></p></li></ul><br><ul><li><p><span style=\"background-color: transparent;\">Spotfire Enterprise Runtime for R - Server Edition 1.12.7 and earlier: upgrade to version 1.12.8 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Enterprise Runtime for R - Server Edition 1.13.0, 1.14.0, 1.15.0, 1.16.0, 1.17.0, 1.17.1, 1.17.2, 1.17.3: upgrade to version 1.17.4 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Enterprise Runtime for R - Server Edition 1.18.0, 1.19.0, 1.20.0: upgrade to version 1.21.0 or higher</span><span style=\"background-color: transparent;\"><br><br></span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Statistics Services 12.0.7 and earlier: upgrade to version 12.0.8 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Statistics Services 12.1.0, 12.2.0, 12.3.0, 12.3.1, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Statistics Services 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher</span><span style=\"background-color: transparent;\"><br><br></span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher</span><span style=\"background-color: transparent;\"><br><br></span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Desktop 14.3.0 and earlier: upgrade to version 14.4.0 or higher</span><span style=\"background-color: transparent;\"><br><br></span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher</span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire Server 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher</span><span style=\"background-color: transparent;\"><br><br></span></p></li><li><p><span style=\"background-color: transparent;\">Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher</span></p></li></ul></b></div></b>"
                }
            ],
            "value": "*  Spotfire Enterprise Runtime for R (aka TERR) 4.5.0, 5.0.0, 5.1.0, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 6.1.1, 6.1.2: upgrade to version 6.1.3 or higher\n\n\n\n\n\n  *  Spotfire Enterprise Runtime for R - Server Edition 1.12.7 and earlier: upgrade to version 1.12.8 or higher\n\n\n  *  Spotfire Enterprise Runtime for R - Server Edition 1.13.0, 1.14.0, 1.15.0, 1.16.0, 1.17.0, 1.17.1, 1.17.2, 1.17.3: upgrade to version 1.17.4 or higher\n\n\n  *  Spotfire Enterprise Runtime for R - Server Edition 1.18.0, 1.19.0, 1.20.0: upgrade to version 1.21.0 or higher\n\n\n\n\n  *  Spotfire Statistics Services 12.0.7 and earlier: upgrade to version 12.0.8 or higher\n\n\n  *  Spotfire Statistics Services 12.1.0, 12.2.0, 12.3.0, 12.3.1, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher\n\n\n  *  Spotfire Statistics Services 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher\n\n\n\n\n  *  Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher\n\n\n  *  Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher\n\n\n  *  Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher\n\n\n\n\n  *  Spotfire Desktop 14.3.0 and earlier: upgrade to version 14.4.0 or higher\n\n\n\n\n  *  Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11 or higher\n\n\n  *  Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher\n\n\n  *  Spotfire Server 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher\n\n\n\n\n  *  Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher"
        }
    ],
    "impact": {
        "cvss": [
            {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
                "version": "3.1"
            }
        ]
    }
}