CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
89.1%
Vulnerabilities have been identified in IBM SPSS Collaboration and Deployment Services which make the product vulnerable to remote code execution.
VULNERABILITY DETAILS:
CVEID:CVE-2013-4042__ __
DESCRIPTION:
All users of Collaboration and Deployment Services are vulnerable.
CVSS Base Score: 10
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/86418 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVEID:CVE-2013-5370__ __
DESCRIPTION:
All users of Collaboration and Deployment Services are vulnerable.
CVSS Base Score: 10
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/86658 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:L/C:C/I:C/A:C)
AFFECTED PRODUCTS AND VERSIONS:
Collaboration and Deployment Services, version 5.0 fix pack 2 and earlier.
REMEDIATION:
Product | VRMF | APAR | Remediation/First Fix |
---|---|---|---|
Collaboration and Deployment Services | 4.2.1 | PM95738 | Fix |
Collaboration and Deployment Services | 5.0.0.0 | PM95738 | Fix |
Workaround(s) & Mitigation(s):
None
REFERENCES:
ยท Complete CVSS Guide
ยท On-line Calculator V2_ _
ยท X-Force Vulnerability Database
ยท CVE-2013-4042__ __
ยท CVE-2013-5370__ __
RELATED INFORMATION:
IBM Product Security Incident Response Program
_IBM Secure Engineering Web Portal _
IBM Product Security Incident Response Blog
ACKNOWLEDGEMENT
None
CHANGE HISTORY
26 September 2013: Original Copy Published
_*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _
_Note: _According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an โindustry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.โ IBM PROVIDES THE CVSS SCORES โAS ISโ WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
Need more help? Our C&DS forum is Live!
[{โProductโ:{โcodeโ:โSS69YHโ,โlabelโ:โIBM SPSS Collaboration and Deployment Servicesโ},โBusiness Unitโ:{โcodeโ:โBU059โ,โlabelโ:โIBM Software w/o TPSโ},โComponentโ:โโโ,โPlatformโ:[{โcodeโ:โPF025โ,โlabelโ:โPlatform Independentโ}],โVersionโ:โ5.0;4.2.1โ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB10โ,โlabelโ:โData and AIโ}}]
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | spss_collaboration_and_deployment_services | 5.0 | cpe:2.3:a:ibm:spss_collaboration_and_deployment_services:5.0:*:*:*:*:*:*:* |
ibm | spss_collaboration_and_deployment_services | 4.2.1 | cpe:2.3:a:ibm:spss_collaboration_and_deployment_services:4.2.1:*:*:*:*:*:*:* |