First published: Sat Dec 21 2013(Updated: )
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Collaboration and Deployment Services | =4.2.1 | |
IBM SPSS Collaboration and Deployment Services | =4.2.1.1 | |
IBM SPSS Collaboration and Deployment Services | =4.2.1.2 | |
IBM SPSS Collaboration and Deployment Services | =4.2.1.3 | |
IBM SPSS Collaboration and Deployment Services | =5.0.0 | |
IBM SPSS Collaboration and Deployment Services | =5.0.0.1 | |
IBM SPSS Collaboration and Deployment Services | =5.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4070 has been classified as a moderate severity vulnerability.
To address CVE-2013-4070, update IBM SPSS Collaboration and Deployment Services to version 4.2.1.3 IF3 or 5.0 FP3 or later.
IBM SPSS Collaboration and Deployment Services 4.2.1 through 4.2.1.2 and version 5.0 before FP3 are affected by CVE-2013-4070.
CVE-2013-4070 allows remote attackers to discover internal passwords through unspecified vectors.
There are no specific documented workarounds for CVE-2013-4070; applying the necessary updates is the recommended action.