VYPR
Unrated severityNVD Advisory· Published Jan 1, 2013· Updated Apr 29, 2026

CVE-2012-5769

CVE-2012-5769

Description

IBM SPSS Modeler 14.0–15.0 FP1 is vulnerable to XXE, allowing remote file disclosure, internal HTTP requests, and denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM SPSS Modeler 14.0–15.0 FP1 is vulnerable to XXE, allowing remote file disclosure, internal HTTP requests, and denial of service.

Vulnerability

IBM SPSS Modeler versions 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 are vulnerable to an XML External Entity (XXE) injection flaw. The vulnerability exists in the XML parser when it processes specially crafted XML documents. An attacker can exploit this by embedding an XML external entity declaration along with an entity reference in a document that a victim opens in the application. No special configuration or privilege is required beyond the user opening the malicious file [1].

Exploitation

The attacker must craft an XML document containing a malicious <!ENTITY> declaration that points to external resources. The victim must be tricked into opening this document with IBM SPSS Modeler. The XML parser then resolves the external entity, which can trigger the reading of local files (e.g., file:///etc/passwd) or cause the application to send HTTP requests to internal or external servers, and can also lead to CPU and memory exhaustion due to entity expansion or resource consumption [1].

Impact

Successful exploitation results in potential disclosure of sensitive files from the victim's filesystem. The attacker may also use the victim's system as a pivot to probe or attack intranet servers via HTTP requests. Additionally, the entity resolution can be crafted to consume excessive CPU and memory, leading to a denial of service condition that affects the availability of the application [1].

Mitigation

IBM has released fixes in the form of Fix Packs: for version 14.2 through 15.0, applying the appropriate Fix Pack resolves the issue. Version 15.0 FP2 and later are unaffected. No workarounds are known; users are advised to apply the recommended updates as soon as practical [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

13
  • IBM/Spss Modeler13 versions
    cpe:2.3:a:ibm:spss_modeler:14.0.0.0:*:*:*:*:*:*:*+ 12 more
    • cpe:2.3:a:ibm:spss_modeler:14.0.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.0.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.0.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:14.2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:15.0.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:spss_modeler:15.0.0.1:*:*:*:*:*:*:*
    • (no CPE)range: 14.0, 14.1, 14.2 FP3, 15.0 before FP2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.