7.5
CVE-2024-31896
- EPSS 0.19%
- Veröffentlicht 25.03.2025 18:58:38
- Zuletzt bearbeitet 18.08.2025 19:49:58
- Erkennungen
IBM SPSS Statistics information disclosure
IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ SPSS Statistics Version 26.0.0.0
Ibm ≫ SPSS Statistics Version 27.0.1.0
Ibm ≫ SPSS Statistics Version 28.0.1.0
Ibm ≫ SPSS Statistics Version 29.0.2.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| IBM | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
https://www.ibm.com/support/pages/node/7228971