CVE-2015-4991

UnknownEPSS 0.30%

Last modified

CVE-2015-4991 is a vulnerability of currently unknown severity. IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.

Description

IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.

Metrics

EPSS Probability
0.30%

21.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IbmSpss Modeler14.2.0.0
IbmSpss Modeler14.2.0.1
IbmSpss Modeler14.2.0.2
IbmSpss Modeler14.2.0.3
IbmSpss Modeler15.0.0.0
IbmSpss Modeler15.0.0.1
IbmSpss Modeler15.0.0.2
IbmSpss Modeler15.0.0.3
IbmSpss Modeler16.0.0.0
IbmSpss Modeler16.0.0.1
IbmSpss Modeler16.0.0.2
IbmSpss Modeler17.0.0.0
IbmSpss Modeler17.0.0.1
IbmSpss Modeler17.1.0.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-4991?
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.
How severe is CVE-2015-4991?
Severity scoring for CVE-2015-4991 is pending analysis. The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.
How do I fix CVE-2015-4991?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-4991?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST