Privilege Escalation Vulnerability in IBM SPSS Statistics
CVE-2015-7489
7.8HIGH
What is CVE-2015-7489?
IBM SPSS Statistics versions 22.0.0.2 before IF10 and 23.0.0.2 before IF7 have a vulnerability due to improper permission settings. The software allows local users to alter Python scripts because of assigned weak permissions, specifically allowing 'Everyone: Write' access. This misconfiguration potentially enables unauthorized users to gain elevated privileges through modification of existing scripts, leading to further exploitation of the affected systems.