The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/86419 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI07828 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21661169 | vendor advisory |