CVE-2012-5769

IBM SPSS Modeler 14.0-15.0 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80316
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM79454
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21620758
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg24034122

Scores

EPSS 0.0144
EPSS Percentile 70.4%

Details

Status published
Products (12)
ibm/spss_modeler 14.0.0.0
ibm/spss_modeler 14.0.0.1
ibm/spss_modeler 14.0.0.2
ibm/spss_modeler 14.1.0.0
ibm/spss_modeler 14.1.0.1
ibm/spss_modeler 14.1.0.2
ibm/spss_modeler 14.2.0.0
ibm/spss_modeler 14.2.0.1
ibm/spss_modeler 14.2.0.2
ibm/spss_modeler 14.2.0.3
... and 2 more
Published Jan 01, 2013
Tracked Since Feb 18, 2026