A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187727.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6427901 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/187727 | vdb entry vendor advisory |