CVE-2023-33842

IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a local user to decrypt and obtain sensitive information. IBM X-Force ID: 256117.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:spss_modeler:17.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.5:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 6.2
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/256117 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/256117 - VDB Entry, Vendor Advisory
References () https://https://www.ibm.com/support/pages/node/7004299 - Broken Link, Patch, Vendor Advisory () https://https://www.ibm.com/support/pages/node/7004299 - Broken Link, Patch, Vendor Advisory

28 Jun 2023, 15:08

Type Values Removed Values Added
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:17.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spss_modeler:18.5:*:*:*:*:*:*:*
First Time Apple
Ibm
Apple macos
Ibm spss Modeler
Microsoft
Microsoft windows
References (MISC) https://https://www.ibm.com/support/pages/node/7004299 - (MISC) https://https://www.ibm.com/support/pages/node/7004299 - Broken Link, Patch, Vendor Advisory
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/256117 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/256117 - VDB Entry, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo

22 Jun 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-22 02:15

Updated : 2024-11-21 08:06


NVD link : CVE-2023-33842

Mitre link : CVE-2023-33842

CVE.ORG link : CVE-2023-33842


JSON object : View

Products Affected

apple

  • macos

ibm

  • spss_modeler

microsoft

  • windows