Local Denial of Service in IBM SPSS Statistics for Windows
CVE-2021-38959
6.2MEDIUM
Summary
IBM SPSS Statistics for Windows versions 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 contains a vulnerability that enables local users to cause a denial of service. This occurs when a user gains unauthorized write access to admin protected directories, leading to potential disruption of services. This flaw highlights the necessity for strict access controls and regular software updates to mitigate misuse.
Affected Version(s)
SPSS Statistics 24.0
SPSS Statistics 27.0.1
SPSS Statistics 25.0
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved