An IBM SPSS Statistics scripts permissions error can allow local users to gain elevated privileges, the company is reporting.
IBM's bulletin reported the vulnerability (CVE-2015-7489) on December 29. The report said the issue impacts IBM SPSS Statistics versions 188.8.131.52 and 184.108.40.206, which use a python scripts that have write permissions to Everyone. This would allow a local user to add malicious OS commands to the python code.
“These command will later be executed in case another user (for example an administrator) opens SPSS and uses that module,” IBM said in the bulletin.
IBM has issued interim fixes, 220.127.116.11-10 and 18.104.22.168-7 22.214.171.124-7, for both versions of the affected software.
IBM SPSS Statistics is a family of analytical products to include planning, data collection and analysis.