PT-2013-1843 · Ibm · Ibm Spss Modeler

Alexey Osipov

+2

·

Published

2013-01-01

·

Updated

2017-08-29

·

CVE-2012-5769

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM SPSS Modeler versions 14.0 through 14.2 FP3 IBM SPSS Modeler version 15.0 before FP2
Description The issue allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service due to CPU and memory consumption. This is achieved via an XML external entity declaration in conjunction with an entity reference.
Recommendations For IBM SPSS Modeler versions 14.0 through 14.2 FP3, update to a version after FP3 to resolve the issue. For IBM SPSS Modeler version 15.0 before FP2, update to FP2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-5769

Affected Products

Ibm Spss Modeler