4

CVE-2015-4991

IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.

Data is provided by the National Vulnerability Database (NVD)
IbmSPSS Modeler Version14.2.0.0
IbmSPSS Modeler Version14.2.0.1
IbmSPSS Modeler Version14.2.0.2
IbmSPSS Modeler Version14.2.0.3
IbmSPSS Modeler Version15.0.0.0
IbmSPSS Modeler Version15.0.0.1
IbmSPSS Modeler Version15.0.0.2
IbmSPSS Modeler Version15.0.0.3
IbmSPSS Modeler Version16.0.0.0
IbmSPSS Modeler Version16.0.0.1
IbmSPSS Modeler Version16.0.0.2
IbmSPSS Modeler Version17.0.0.0
IbmSPSS Modeler Version17.0.0.1
IbmSPSS Modeler Version17.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.087
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 2.5 1.4
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.