PT-2013-4816 · Ibm · Ibm Spss Analytical Decision Management
Publicado
2013-09-16
·
Atualizado
2017-08-29
·
CVE-2013-4049
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM SPSS Analytical Decision Management versions 6.1 through 6.1 before IF1
IBM SPSS Analytical Decision Management versions 6.2 through 6.2 before IF1
IBM SPSS Analytical Decision Management versions 7.0 through 7.0 before FP1 IF6
Description
The issue allows remote authenticated users to execute arbitrary code by uploading and accessing a JSP file, due to an unrestricted file upload vulnerability.
Recommendations
For IBM SPSS Analytical Decision Management versions 6.1 through 6.1 before IF1, apply the IF1 patch to resolve the issue.
For IBM SPSS Analytical Decision Management versions 6.2 through 6.2 before IF1, apply the IF1 patch to resolve the issue.
For IBM SPSS Analytical Decision Management versions 7.0 through 7.0 before FP1 IF6, apply the FP1 IF6 patch to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Spss Analytical Decision Management