First published: Tue Jan 01 2013(Updated: )
IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Modeler | =14.0.0.0 | |
IBM SPSS Modeler | =14.0.0.1 | |
IBM SPSS Modeler | =14.0.0.2 | |
IBM SPSS Modeler | =14.1.0.0 | |
IBM SPSS Modeler | =14.1.0.1 | |
IBM SPSS Modeler | =14.1.0.2 | |
IBM SPSS Modeler | =14.2.0.0 | |
IBM SPSS Modeler | =14.2.0.1 | |
IBM SPSS Modeler | =14.2.0.2 | |
IBM SPSS Modeler | =14.2.0.3 | |
IBM SPSS Modeler | =15.0.0.0 | |
IBM SPSS Modeler | =15.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.