QID 379487
Date Published: 2024-03-18
QID 379487: IBM SPSS Statistics Denial of Service (DoS) Vulnerability (7130881)
IBM SPSS Statistics is a software package used for interactive, or batched, statistical analysis.
CVE-2022-43855: The IO Module is a separate library that users can code to read and write SPSS .sav data files. A vulnerability was discovered in which attempts to write to an unwritable location can lead to file handle leakage and eventual file handle exhaustion.
Affected Versions
IBM SPSS Statistics 28.0.
IBM SPSS Statistics 26.0.
IBM SPSS Statistics 27.0.1.
QID Detection Logic(Authenticated)
It checks for vulnerable versions of IBM SPSS Statistics by checking its file version.
Successful exploits could allow local users to create multiple files that could exhaust the file handle capacity and cause a denial of service.
Solution
Customers are advised to install latest version of IBM Statistics 7130881 to remediate this vulnerability.
Vendor References
- 7130881 -
www.ibm.com/support/pages/node/7130881
CVEs related to QID 379487
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7130881 |
|