First published: Tue Mar 09 2021(Updated: )
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Modeler Subscription | <=Subscription | |
IBM SPSS Modeler Subscription |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4717 is classified as a medium severity vulnerability due to its potential for unauthorized file writing.
To mitigate CVE-2020-4717, ensure that users do not have create symbolic link permissions during the installation of IBM SPSS Modeler Subscription.
Exploitation of CVE-2020-4717 could allow an attacker to write arbitrary files to protected paths, potentially leading to unauthorized access or system compromise.
CVE-2020-4717 affects users of IBM SPSS Modeler Subscription who have permissions to create symbolic links during installation.
A practical workaround for CVE-2020-4717 includes restricting user permissions related to creating symbolic links in vulnerable environments.