PT-2012-2387 · Ibm · Ibm Spss Samplepower
Andrea Micalizza
+1
·
Published
2012-01-18
·
Updated
2017-08-29
·
CVE-2012-0189
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM SPSS SamplePower version 3.0
Description
The issue concerns unspecified vulnerabilities in the PrintFile and SaveDoc methods of the VsVIEW6 ActiveX control. These vulnerabilities allow remote attackers to execute arbitrary code via a crafted HTML document.
Recommendations
For IBM SPSS SamplePower version 3.0, consider disabling the VsVIEW6 ActiveX control until a patch is available.
As a temporary workaround, restrict access to the SaveDoc and PrintFile methods in the VsVIEW6 ActiveX control to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Spss Samplepower