Known vulnerabilities in IBM SPSS Analytic Server - page 3

Software CPE: cpe:2.3:a:ibm_corporation:ibm_spss_analytic_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 68
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM SPSS Analytic Server IBM SPSS Analytic Server is affected by 68 known vulnerabilities: 9 high, 47 medium, 12 low Critical High Medium Low

Vulnerabilities (68)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114346 - Command injection
CVE-2025-7962
CWE-77 Medium
No
No
- 21.08.2025 SB2025082145
SB2025082146
SB2025082147
and 54 more
#VU111165 - Improper Access Control
CVE-2025-48734
CWE-284 Medium
No
No
- 16.06.2025 SB2025061643
SB2025061644
SB2025061645
and 141 more
#VU105112 - Resource exhaustion
CVE-2025-23184
CWE-400 Medium
No
No
- 28.02.2025 SB2025022807
SB2025030340
SB2025041017
and 40 more
#VU103769 - Resource exhaustion
CVE-2025-25193
CWE-400 Low
No
No
- 11.02.2025 SB2025021186
SB202502197190
SB2025030409
and 56 more
#VU100259 - Resource Management Errors
CVE-2024-47535
CWE-399 Low
No
No
- 12.11.2024 SB2024111299
SB2024122313
SB2025012061
and 79 more
#VU98137 - Allocation of Resources Without Limits or Throttling
CVE-2024-40094
CWE-770 Medium
Available
No
- 08.10.2024 SB2024100835
SB2024100936
SB2024101593
and 27 more
#VU97574 - Uncontrolled Recursion
CVE-2024-7254
CWE-674 Medium
No
No
- 19.09.2024 SB2024091904
SB2024100103
SB2024101050
and 90 more
#VU96058 - Exposure of sensitive information to an unauthorized actor
CVE-2023-50314
CWE-200 Low
No
No
- 15.08.2024 SB2024081566
SB2024091324
SB2024091814
and 44 more
#VU88977 - Resource exhaustion
CVE-2024-25026
CWE-400 Medium
No
No
- 24.04.2024 SB2024042458
SB2024042525
SB2024042626
and 68 more
#VU88803 - Server-Side Request Forgery (SSRF)
CVE-2024-22329
CWE-918 Medium
No
No
- 18.04.2024 SB2024041812
SB2024042613
SB2024043016
and 67 more
#VU88802 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-22354
CWE-611 High
No
No
- 18.04.2024 SB2024041812
SB2024042628
SB2024050920
and 66 more
#VU88173 - Resource exhaustion
CVE-2023-51775
CWE-400 Medium
No
No
- 05.04.2024 SB2024040525
SB2024041129
SB2024041130
and 83 more
#VU88136 - Resource exhaustion
CVE-2024-27268
CWE-400 Medium
No
No
- 04.04.2024 SB2024040437
SB2024050803
SB2024052003
and 40 more
#VU88123 - Resource exhaustion
CVE-2024-22353
CWE-400 Medium
No
No
- 04.04.2024 SB2024040423
SB2024050220
SB2024050801
and 31 more
#VU87831 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-27270
CWE-79 Medium
No
No
- 26.03.2024 SB2024032654
SB2024050220
SB2024050920
and 31 more
#VU87779 - Exposure of sensitive information to an unauthorized actor
CVE-2024-29025
CWE-200 Medium
No
No
- 25.03.2024 SB2024032532
SB2024040230
SB2024042995
and 95 more
#VU79665 - Improper input validation
CVE-2023-38737
CWE-20 Medium
No
No
- 17.08.2023 SB2023081721
SB2023100203
SB2023100308
and 20 more
#VU70119 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2022-41915
CWE-113 Medium
No
No
- 12.12.2022 SB2022121215
SB2023011210
SB2023013027
and 25 more
#VU18668 - Improper Access Control
CVE-2019-0201
CWE-284 Low
No
No
- 04.06.2019 SB2019061213
SB2019102004
SB2019112016
and 10 more
#VU12913 - Improper Authentication
CVE-2018-8012
CWE-287 Low
No
No
- 22.05.2018 SB2018052204
SB2018060404
SB2022072128
and 4 more


Showing elements 41 - 60 out of 68