Data Exposure Vulnerability in IBM SPSS Modeler
CVE-2015-4991

4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
15 February 2016

Summary

IBM SPSS Modeler versions 14.2 to 17.1 contain a vulnerability that results in the exposure of sensitive cleartext data within memory dumps. This flaw allows local users to gain unauthorized access to potentially sensitive information stored in these dump files. As such, it poses a risk of data leakage that could be exploited for malicious purposes.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.