SB2026092423 - IBM SPSS Modeler update for Apache Hive
Published: September 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2026-55976)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.
The vulnerability exists due to insufficient input validation in Hive Avro SerDe schema resolution when resolving the avro.schema.url table property on an Avro table that is subsequently queried. A remote user can create a crafted Avro table with a malicious avro.schema.url value to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.
Exploitation requires the ability to create a table, and external tables are typically required in practice.
Remediation
Install update from vendor's website.