CVE-2014-3038: IBM Spss Modeler
Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
Affected products
- IBM Spss Modeler: version 16.0.0.0 only
Published 2014-06-08. Last modified 2026-06-17.