SB2026092423 - IBM SPSS Modeler update for Apache Hive



SB2026092423 - IBM SPSS Modeler update for Apache Hive

Published: September 24, 2026

Security Bulletin ID SB2026092423
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-55976)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.

The vulnerability exists due to insufficient input validation in Hive Avro SerDe schema resolution when resolving the avro.schema.url table property on an Avro table that is subsequently queried. A remote user can create a crafted Avro table with a malicious avro.schema.url value to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.

Exploitation requires the ability to create a table, and external tables are typically required in practice.


Remediation

Install update from vendor's website.