CVE-2015-0140: IBM Spss Statistics

Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.

Affected products

  • IBM Spss Statistics: version 22.0 only

Published 2015-05-25. Last modified 2026-06-17.