CVE-2024-3330

Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than the attacker., In the case of the Web player (Business Author): Successful execution of this vulnerability via the Web Player, will result in the attacker being able to run arbitrary code as the account running the Web player process, In the case of Automation Services: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code via Automation Services..This issue affects Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0 through 14.0.2; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0 through 14.0.3, from 14.2.0 through 14.3.0; Spotfire for AWS Marketplace: from 14.0 before 14.3.0.
Configurations

No configuration.

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3330-r3435/ - () https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-june-262024-spotfire-cve-2024-3330-r3435/ -

01 Aug 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire para AWS Marketplace permite En el caso del cliente de Windows instalado: la ejecución exitosa de esta vulnerabilidad dará como resultado que un atacante pueda ejecutar código arbitrario. Esto requiere la interacción humana de otra persona. que el atacante. En el caso del reproductor web (autor comercial): la ejecución exitosa de esta vulnerabilidad a través del reproductor web dará como resultado que el atacante pueda ejecutar código arbitrario como la cuenta que ejecuta el proceso del reproductor web. de Automation Services: la ejecución exitosa de esta vulnerabilidad dará como resultado que un atacante pueda ejecutar código arbitrario a través de Automation Services. Este problema afecta a Spotfire Analyst: desde 12.0.9 hasta 12.5.0, desde 14.0 hasta 14.0.2; Servidor Spotfire: de 12.0.10 a 12.5.0, de 14.0 a 14.0.3, de 14.2.0 a 14.3.0; Spotfire para AWS Marketplace: desde 14.0 antes de 14.3.0.
CWE CWE-250

27 Jun 2024, 19:25

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 19:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3330

Mitre link : CVE-2024-3330

CVE.ORG link : CVE-2024-3330


JSON object : View

Products Affected

No product.

CWE
CWE-250

Execution with Unnecessary Privileges