Remote File Access Vulnerability in IBM SPSS Modeler Software
CVE-2012-5769 
Currently unrated
What is CVE-2012-5769?
IBM SPSS Modeler versions 14.0, 14.1, and 14.2 (through FP3), along with 15.0 (before FP2) are susceptible to an XML external entity declaration vulnerability. This flaw allows remote attackers to leverage the application's XML parsing capabilities to read arbitrary files on the server. Additionally, it can enable attackers to issue HTTP requests to internal network servers or potentially trigger denial of service conditions by consuming excessive CPU and memory resources.