VulnerabilityModified
CVE-2023-33842
IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a local user to decrypt and obtain sensitive information.
MEDIUM 5.5EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a local user to decrypt and obtain sensitive information. IBM X-Force ID: 256117.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Affected
- ibm/spss modeler
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/256117VDB Entry, Vendor Advisory
- https://https://www.ibm.com/support/pages/node/7004299Broken Link, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/256117VDB Entry, Vendor Advisory
- https://https://www.ibm.com/support/pages/node/7004299Broken Link, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.