Vulnerability Name: | CVE-2012-0190 (CCN-72121) | ||||||||
Assigned: | 2011-12-14 | ||||||||
Published: | 2012-01-03 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-0190 Source: CCN Type: SA47565 IBM SPSS Data Collection ActiveX Controls Two Vulnerabilities Source: SECUNIA Type: Vendor Advisory 47565 Source: CCN Type: IBM Web site IBM SPSS software for predictive analytics Source: CCN Type: IBM Security Bulletin 1577956 Security Bulletin: IBM SPSS Data Collection ActiveX Control vulnerabilities (CVE-2012-0188, CVE-2012-0190) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21577956 Source: CCN Type: OSVDB ID: 78330 IBM SPSS Data Collection ActiveX (ExportHTML.ocx) Render() Method Handling Remote Code Execution Source: CCN Type: BID-51445 IBM SPSS Data Collection and Dimensions ActiveX Control Remote Code Execution Vulnerabilities Source: XF Type: UNKNOWN spss-wxporthtml-activex-code-execution(72121) Source: XF Type: UNKNOWN spss-wxporthtml-activex-code-execution(72121) Source: CCN Type: ZDI-12-026 IBM SPSS ExportHTML.dll ActiveX Control Render Method Remote Code Execution Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |