Known vulnerabilities in IBM SPSS Analytic Server - page 4

Software CPE: cpe:2.3:a:ibm_corporation:ibm_spss_analytic_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 79
Public exploits: 6
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM SPSS Analytic Server IBM SPSS Analytic Server is affected by 79 known vulnerabilities: 9 high, 53 medium, 17 low Critical High Medium Low

Vulnerabilities (79)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU97574 - Uncontrolled Recursion
CVE-2024-7254
CWE-674 Medium
No
No
- 19.09.2024 SB2024091904
SB2024100103
SB2024101050
and 90 more
#VU96058 - Exposure of sensitive information to an unauthorized actor
CVE-2023-50314
CWE-200 Low
No
No
- 15.08.2024 SB2024081566
SB2024091324
SB2024091814
and 44 more
#VU88977 - Resource exhaustion
CVE-2024-25026
CWE-400 Medium
No
No
- 24.04.2024 SB2024042458
SB2024042525
SB2024042626
and 68 more
#VU88803 - Server-Side Request Forgery (SSRF)
CVE-2024-22329
CWE-918 Medium
No
No
- 18.04.2024 SB2024041812
SB2024042613
SB2024043016
and 67 more
#VU88802 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-22354
CWE-611 High
No
No
- 18.04.2024 SB2024041812
SB2024042628
SB2024050920
and 66 more
#VU88173 - Resource exhaustion
CVE-2023-51775
CWE-400 Medium
No
No
- 05.04.2024 SB2024040525
SB2024041129
SB2024041130
and 83 more
#VU88136 - Resource exhaustion
CVE-2024-27268
CWE-400 Medium
No
No
- 04.04.2024 SB2024040437
SB2024050803
SB2024052003
and 40 more
#VU88123 - Resource exhaustion
CVE-2024-22353
CWE-400 Medium
No
No
- 04.04.2024 SB2024040423
SB2024050220
SB2024050801
and 31 more
#VU87831 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-27270
CWE-79 Medium
No
No
- 26.03.2024 SB2024032654
SB2024050220
SB2024050920
and 31 more
#VU87779 - Exposure of sensitive information to an unauthorized actor
CVE-2024-29025
CWE-200 Medium
No
No
- 25.03.2024 SB2024032532
SB2024040230
SB2024042995
and 95 more
#VU73970 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-48285
CWE-22 Medium
No
No
- 23.03.2023 SB2023032314
SB2023032315
SB2023042510
and 22 more
#VU72075 - Insecure Temporary File
CVE-2023-0482
CWE-377 Low
No
No
- 08.02.2023 SB2023020877
SB2023033003
SB2023033004
and 36 more
#VU70119 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2022-41915
CWE-113 Medium
No
No
- 12.12.2022 SB2022121215
SB2023011210
SB2023013027
and 25 more
#VU69209 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-34165
CWE-444 Medium
No
No
- 10.11.2022 SB2022111029
SB2022111104
SB2022111409
and 58 more
#VU64957 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-33980
CWE-94 High
Available
No
3.4.0.0.1 06.07.2022 SB2022070645
SB2022072604
SB2022081517
and 31 more
#VU64197 - Improper Authentication
CVE-2022-22475
CWE-287 Low
No
No
- 13.06.2022 SB2022061307
SB2022061310
SB2022062218
and 26 more
#VU59970 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2021-39031
CWE-90 Medium
No
No
- 25.01.2022 SB2022012506
SB2022032317
SB2022041207
and 12 more
#VU59051 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-45105
CWE-835 Medium
Available
No
- 18.12.2021 SB2021121802
SB2021121903
SB2021122011
and 169 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
- 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more


Showing elements 61 - 80 out of 79