CVE-2012-5769: IBM Spss Modeler
Medium severity, CVSS 5.8. EPSS: 1.4% chance of exploitation in the next 30 days.
IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
Affected products
- IBM Spss Modeler: version 14.0.0.0 only; version 14.0.0.1 only; version 14.0.0.2 only; version 14.1.0.0 only; version 14.1.0.1 only; version 14.1.0.2 only; …
Published 2013-01-01. Last modified 2026-06-16.