SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3038

IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.

LOW 3.6EPSS 0.33%

Does this matter?

Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.

Description

IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.

CVSS 2.0
3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
EPSS
0.33% probability · 26th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
ibm/spss modeler
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.