CVE Vulnerabilities

CVE-2012-5769

Published: Jan 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.

Affected Software

NameVendorStart VersionEnd Version
Spss_modelerIbm14.0.0.0 (including)14.0.0.0 (including)
Spss_modelerIbm14.0.0.1 (including)14.0.0.1 (including)
Spss_modelerIbm14.0.0.2 (including)14.0.0.2 (including)
Spss_modelerIbm14.1.0.0 (including)14.1.0.0 (including)
Spss_modelerIbm14.1.0.1 (including)14.1.0.1 (including)
Spss_modelerIbm14.1.0.2 (including)14.1.0.2 (including)
Spss_modelerIbm14.2.0.0 (including)14.2.0.0 (including)
Spss_modelerIbm14.2.0.1 (including)14.2.0.1 (including)
Spss_modelerIbm14.2.0.2 (including)14.2.0.2 (including)
Spss_modelerIbm14.2.0.3 (including)14.2.0.3 (including)
Spss_modelerIbm15.0.0.0 (including)15.0.0.0 (including)
Spss_modelerIbm15.0.0.1 (including)15.0.0.1 (including)

References