CVE-2024-3331

Spotfire: NTLM token leakage

Description

Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue affects Spotfire Enterprise Runtime for R - Server Edition: from 1.12.7 through 1.20.0; Spotfire Statistics Services: from 12.0.7 through 12.3.1, from 14.0.0 through 14.3.0; Spotfire Analyst: from 12.0.9 through 12.5.0, from 14.0.0 through 14.3.0; Spotfire Desktop: from 14.0 through 14.3.0; Spotfire Server: from 12.0.10 through 12.5.0, from 14.0.0 through 14.3.0.

Remediation

Solution:

  • * Spotfire Enterprise Runtime for R (aka TERR) 4.5.0, 5.0.0, 5.1.0, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 6.1.1, 6.1.2: upgrade to version 6.1.3 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.12.7 and earlier: upgrade to version 1.12.8 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.13.0, 1.14.0, 1.15.0, 1.16.0, 1.17.0, 1.17.1, 1.17.2, 1.17.3: upgrade to version 1.17.4 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.18.0, 1.19.0, 1.20.0: upgrade to version 1.21.0 or higher * Spotfire Statistics Services 12.0.7 and earlier: upgrade to version 12.0.8 or higher * Spotfire Statistics Services 12.1.0, 12.2.0, 12.3.0, 12.3.1, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Statistics Services 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher * Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher * Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire Desktop 14.3.0 and earlier: upgrade to version 14.4.0 or higher * Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11 or higher * Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Server 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher

Category

6.8
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.07%
Affected: Spotfire Spotfire Enterprise Runtime for R - Server Edition
Affected: Spotfire Spotfire Statistics Services
Affected: Spotfire Spotfire Analyst
Affected: Spotfire Spotfire Desktop
Affected: Spotfire Spotfire Server
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-3331?
CVE-2024-3331 has been scored as a medium severity vulnerability.
How to fix CVE-2024-3331?
To fix CVE-2024-3331: * Spotfire Enterprise Runtime for R (aka TERR) 4.5.0, 5.0.0, 5.1.0, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 6.1.1, 6.1.2: upgrade to version 6.1.3 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.12.7 and earlier: upgrade to version 1.12.8 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.13.0, 1.14.0, 1.15.0, 1.16.0, 1.17.0, 1.17.1, 1.17.2, 1.17.3: upgrade to version 1.17.4 or higher * Spotfire Enterprise Runtime for R - Server Edition 1.18.0, 1.19.0, 1.20.0: upgrade to version 1.21.0 or higher * Spotfire Statistics Services 12.0.7 and earlier: upgrade to version 12.0.8 or higher * Spotfire Statistics Services 12.1.0, 12.2.0, 12.3.0, 12.3.1, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Statistics Services 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire Analyst 12.0.9 and earlier: upgrade to version 12.0.10 or higher * Spotfire Analyst 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2: upgrade to version 14.0.3 or higher * Spotfire Analyst 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire Desktop 14.3.0 and earlier: upgrade to version 14.4.0 or higher * Spotfire Server 12.0.10 and earlier: upgrade to version 12.0.11 or higher * Spotfire Server 12.1.0, 12.1.1, 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.0.1, 14.0.2, 14.0.3: upgrade to version 14.0.4 or higher * Spotfire Server 14.1.0, 14.2.0, 14.3.0: upgrade to version 14.4.0 or higher * Spotfire for AWS Marketplace 14.3.0 and earlier: upgrade to version 14.4.0 or higher
Is CVE-2024-3331 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-3331 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-3331?
CVE-2024-3331 affects Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.