CVE-2014-0920
IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 - Authenticated Cleartext Password Exposure
Title source: llmDescription
IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/92073
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI13527
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21669506
Scores
EPSS
0.0162
EPSS Percentile
73.6%
Details
CWE
CWE-255
Status
published
Products (2)
ibm/spss_analytic_server
1.0.0.0
ibm/spss_analytic_server
1.0.1.0
Published
Apr 10, 2014
Tracked Since
Feb 18, 2026