VendorsIBMspss_statisticsall versions
Vulnerabilities

IBM SPSS Statistics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2015-7489
IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.
Published 2016-01-01 · Modified
7.8EPSS 0.004
CVE-2024-31896
IBM SPSS Statistics information disclosure
Published 2025-03-25 · Analyzed
7.5EPSS 0.002
CVE-2015-0140
An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.
Published 2015-05-25 · Modified
6.8EPSS 0.019
CVE-2015-8530
Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows remote authenticated users to execute arbitrary code via a long argument.
Published 2016-05-14 · Modified
6.5EPSS 0.015
CVE-2021-38959
IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046.
Published 2021-11-17 · Modified
6.2EPSS 0.002
CVE-2022-43855
IBM SPSS Statistics denial of service
Published 2024-03-08 · Modified
6.2EPSS 0.002