First published: Mon Sep 16 2013(Updated: )
Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to execute arbitrary code by uploading and accessing a JSP file.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Analytical Decision Management | =6.1.0.0 | |
IBM SPSS Analytical Decision Management | =6.2.0.0 | |
IBM SPSS Analytical Decision Management | =7.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4049 is considered a critical vulnerability due to the ability for authenticated users to execute arbitrary code.
To fix CVE-2013-4049, users should update to IBM SPSS Analytical Decision Management version 6.1 IF1, 6.2 IF1, or 7.0 FP1 IF6.
CVE-2013-4049 affects IBM SPSS Analytical Decision Management versions 6.1.0.0, 6.2.0.0, and 7.0.0.0.
No, CVE-2013-4049 requires remote authenticated users to exploit the vulnerability.
CVE-2013-4049 enables remote code execution attacks through unrestricted file uploads.