4

CVE-2015-4991

IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ SPSS Modeler Version 14.2.0.0
Ibm ≫ SPSS Modeler Version 14.2.0.1
Ibm ≫ SPSS Modeler Version 14.2.0.2
Ibm ≫ SPSS Modeler Version 14.2.0.3
Ibm ≫ SPSS Modeler Version 15.0.0.0
Ibm ≫ SPSS Modeler Version 15.0.0.1
Ibm ≫ SPSS Modeler Version 15.0.0.2
Ibm ≫ SPSS Modeler Version 15.0.0.3
Ibm ≫ SPSS Modeler Version 16.0.0.0
Ibm ≫ SPSS Modeler Version 16.0.0.1
Ibm ≫ SPSS Modeler Version 16.0.0.2
Ibm ≫ SPSS Modeler Version 17.0.0.0
Ibm ≫ SPSS Modeler Version 17.0.0.1
Ibm ≫ SPSS Modeler Version 17.1.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.218
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 2.5 1.4
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www-01.ibm.com/support/docview.wss?uid=swg1PI46224
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21975663
Vendor Advisory