First published: Fri Jan 01 2016(Updated: )
IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Statistics for Windows | =22.0.0.2 | |
IBM SPSS Statistics for Windows | =23.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7489 is rated as a medium severity vulnerability due to the potential for privilege escalation.
To fix CVE-2015-7489, update to IBM SPSS Statistics version 22.0.0.2 IF10 or 23.0.0.2 IF7 or later.
CVE-2015-7489 affects users of IBM SPSS Statistics versions 22.0.0.2 before IF10 and 23.0.0.2 before IF7.
CVE-2015-7489 is a local privilege escalation vulnerability caused by weak script permissions.
Yes, local users can exploit CVE-2015-7489 by modifying Python scripts due to weak permissions.