Known vulnerabilities in SPSS Statistics - page 2
Vendor:
IBM Corporation
Software:
SPSS Statistics
Software CPE:
cpe:2.3:a:ibm_corporation:spss_statistics:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
34
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
27.0.1.0 IF036
28.0.1.1 IF018
29.0.2.0 IF019
30.0.0.0 IF015
31.0.2.0 IF007
31.0.2.0 IF06
30.0.0.0 IF014
29.0.2.0 IF018
28.0.1.1 IF017
27.0.1.0 IF035
28.0.1.0
26.0.0.0
31.0.0.0 IF005
30.0.0.0 IF0011
29.0.2.0 IF016
28.0.1.1 IF015
27.0.1.0 IF033
27.0.1.0 IF031
28.0.1.1 IF012
29.0.2.0 IF014
30.0.0.0 IF009
31.0.0.0 IF001
30
29.0.2.0
27.0.1.0
29.0.2
29.0.1.0
29.0
25.0
26.0
25.0.0.2
26.0.0.1
27.0.1
28.0.1
28.0.1.1
Vulnerabilities (34)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112132 - Stack-based buffer overflow CVE-2025-4447 |
CWE-121 | Medium | 27.0.1.0 IF031, 28.0.1.1 IF012, 29.0.2.0 IF014, 30.0.0.0 IF009, 31.0.0.0 IF001 | 03.07.2025 |
SB2025070315 SB2025070316 SB2025070319 and 54 more |
||
| #VU107520 - Improper input validation CVE-2025-21587 |
CWE-20 | Medium | 27.0.1.0 IF031, 28.0.1.1 IF012, 29.0.2.0 IF014, 30.0.0.0 IF009, 31.0.0.0 IF001 | 16.04.2025 |
SB20250416145 SB20250416146 SB20250416147 and 103 more |
||
| #VU107521 - Improper input validation CVE-2025-30698 |
CWE-20 | Medium | 27.0.1.0 IF031, 28.0.1.1 IF012, 29.0.2.0 IF014, 30.0.0.0 IF009, 31.0.0.0 IF001 | 16.04.2025 |
SB20250416145 SB20250416146 SB20250416147 and 93 more |
||
| #VU89063 - Deserialization of Untrusted Data CVE-2024-27322 |
CWE-502 | High | 30 | 30.04.2024 |
SB2024043015 SB20240430102 SB20240430103 and 5 more |
||
| #VU87294 - Resource exhaustion CVE-2022-43855 |
CWE-400 | Low | 29.0.2 | 08.03.2024 |
SB2024030823 |
||
| #VU78901 - Deserialization of Untrusted Data CVE-2022-40609 |
CWE-502 | High | - | 03.08.2023 |
SB2023080307 SB2023080808 SB2023080809 and 56 more |
||
| #VU78413 - Improper input validation CVE-2023-22045 |
CWE-20 | Low | 27.0.1.0, 28.0.1.1, 29.0.2.0 | 19.07.2023 |
SB2023071985 SB2023071986 SB2023071987 and 155 more |
||
| #VU78414 - Improper input validation CVE-2023-22049 |
CWE-20 | Low | 27.0.1.0, 28.0.1.1, 29.0.2.0 | 19.07.2023 |
SB2023071985 SB2023071986 SB2023071987 and 164 more |
||
| #VU75508 - Exposure of sensitive information to an unauthorized actor CVE-2023-30441 |
CWE-200 | Medium | 27.0.1.0, 28.0.1.1 | 26.04.2023 |
SB2023042618 SB2023042749 SB2023050107 and 41 more |
||
| #VU62400 - Improper input validation CVE-2022-21496 |
CWE-20 | Medium | - | 19.04.2022 |
SB2022041944 SB2022041945 SB2022042102 and 118 more |
||
| #VU61671 - Memory corruption CVE-2018-25032 |
CWE-119 | Medium | 29.0.1.0 | 28.03.2022 |
SB2022032844 SB2022032845 SB2022033018 and 192 more |
||
| #VU57487 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2021-35550 |
CWE-300 | Medium | - | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 102 more |
||
| #VU57496 - Improper input validation CVE-2021-35603 |
CWE-20 | Low | - | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 112 more |
||
| #VU14515 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2018-1000632 |
CWE-611 | Low | 29.0 | 21.08.2018 |
SB2018082321 SB2018120722 SB2018121006 and 20 more |
Showing elements 21 - 40 out of 34