Lucene search

K
ibmIBM3DAE2966402FC9EF3964BB1CBD0423B6B41F82063D88DBEC5553181EC28439BA
HistoryNov 02, 2022 - 2:15 a.m.

Security Bulletin: IBM SPSS Modeler is vulnerable to Apache Commons Text [CVE-2022-42889]

2022-11-0202:15:39
www.ibm.com
31
ibm spss modeler
apache commons text
cve-2022-42889
vulnerability
remote code execution
interpolation flaw
cvss
affected products
remediation
fix download link

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.972 High

EPSS

Percentile

99.8%

Summary

Apache Commons Text is used by IBM SPSS Modeler as part of the spark function. This vulnerability is addressed. [CVE-2022-42889]

Vulnerability Details

CVEID:CVE-2022-42889
**DESCRIPTION:**Apache Commons Text could allow a remote attacker to execute arbitrary code on the system, caused by an insecure interpolation defaults flaw. By sending a specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/238560 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM SPSS Modeler|**Version(s)
**
—|—
IBM SPSS Modeler Client| 18.3
IBM SPSS Modeler Server
IBM SPSS Modeler Solution Publisher
IBM SPSS Modeler Collaboration and Deployment Services Adapter
IBM SPSS Modeler Client| 18.4
IBM SPSS Modeler Server
IBM SPSS Modeler Solution Publisher
IBM SPSS Modeler Collaboration and Deployment Services Adapter

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s)|**Version(s)
**|**Fix Download link
**
—|—|—
IBM SPSS Modeler| 18.3| 18.3.0.0-IM-S18MODELER-IF018
IBM SPSS Modeler| 18.4| 18.4.0.0-IM-S18MODELER-IF006

Workarounds and Mitigations

N/A

Affected configurations

Vulners
Node
ibmspss_modelerMatch18.3
OR
ibmspss_modelerMatch18.4
CPENameOperatorVersion
spss modelereq18.3
spss modelereq18.4

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.972 High

EPSS

Percentile

99.8%