The bug, patched recently by IBM, exists because an ActiveX control parameter is insufficiently sanitized, and it can be exploited by passing malicious code through the problematic parameter. The vulnerability has been assigned the CVE identifier CVE-2015-0140 and a CVSS score of 4.1.
The flaw affects SPSS 22 on Windows 32-bit installations. IBM patched the vulnerability with the release of SPSS Statistics 22.0 Fix Pack 1 and the SPSS Statistics 22.0 FP1 IF022 interim fix. The company advises users to install the fix pack and then the interim fix.
spss version 22 full patch
2ff7e9595c
コメント