First published: Tue Mar 25 2025(Updated: )
IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Statistics for Windows | >=26.0<=29.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31896 is considered a moderate severity vulnerability due to the potential exposure of highly sensitive information.
To fix CVE-2024-31896, upgrade IBM SPSS Statistics to a version that uses stronger cryptographic algorithms that do not include 26.0, 27.0.1, 28.0.1, and 29.0.2.
CVE-2024-31896 affects IBM SPSS Statistics versions 26.0, 27.0.1, 28.0.1, and 29.0.2.
The risks associated with CVE-2024-31896 include unauthorized decryption and exposure of sensitive data.
Currently, no official workaround exists for CVE-2024-31896, and upgrading to a secure version is recommended.