Vulnerabilities > IBM > Spss Collaboration AND Deployment Services > 4.2.1

DATE CVE VULNERABILITY TITLE RISK
2014-02-01 CVE-2013-4043 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.
network
low complexity
ibm CWE-200
5.0
2013-12-21 CVE-2013-4070 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.
network
low complexity
ibm CWE-200
5.0
2013-12-21 CVE-2013-4069 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
ibm CWE-200
5.0
2013-12-21 CVE-2013-4046 Improper Input Validation vulnerability in IBM Spss Collaboration and Deployment Services
Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
ibm CWE-20
5.8
2013-12-21 CVE-2013-4045 Cross-Site Scripting vulnerability in IBM Spss Collaboration and Deployment Services
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2013-12-21 CVE-2013-4044 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.
network
low complexity
ibm CWE-200
4.0
2013-10-01 CVE-2013-5370 Unspecified vulnerability in IBM Spss Collaboration and Deployment Services
Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-4042.
network
low complexity
ibm
critical
10.0
2013-10-01 CVE-2013-4042 Unspecified vulnerability in IBM Spss Collaboration and Deployment Services
Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-5370.
network
low complexity
ibm
critical
10.0