PT-2013-4831 · Ibm · Ibm Spss Collaboration/Deployment Services
Published
2013-12-21
·
Updated
2017-08-29
·
CVE-2013-4069
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM SPSS Collaboration and Deployment Services versions 4.2.1 through 4.2.1.3 IF2
IBM SPSS Collaboration and Deployment Services versions 5.0 through FP2
Description
The issue allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. This affects the Portal application.
Recommendations
For IBM SPSS Collaboration and Deployment Services versions 4.2.1 through 4.2.1.3 IF2, update to version 4.2.1.3 IF3.
For IBM SPSS Collaboration and Deployment Services versions 5.0 through FP2, update to version FP3.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spss Collaboration/Deployment Services