Symbolic Link Vulnerability in IBM SPSS Modeler Subscription Installer
CVE-2020-4717
6.2MEDIUM
Summary
A vulnerability exists in the IBM SPSS Modeler Subscription Installer that enables a user with create symbolic link permissions to write files to unauthorized locations during the installation process. This could potentially allow for the execution of malicious code or access to sensitive information, as the restricted paths could be exploited by malicious actors. For more details, refer to IBM's official documentation and vulnerability database.
Affected Version(s)
SPSS Modeler Subscription
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved