PM79454; Vulnerability of an XML injection attack in IBM SPSS Modeler

Downloadable files


Abstract

This Interim Fix addresses an important product correction for SPSS Modeler 14.x and 15.

Download Description

Please refer to the Alert for more information.

RECOMMENDATION:

For Modeler 14.1:
Please contact support to request a 14.1 version of this Interim Fix.

For Modeler 14.2:
Apply the SPSS Modeler Premium 14.2 Interim Fix below. A prerequisite is that you have updated your 14.2 installation to 14.2 Fix Pack 3. Please refer to IBM SPSS Modeler 14.2 Fix Pack 3 for additional details.

For Modeler 15.0:
Apply the SPSS Modeler Premium 15.0 Interim Fix below. A prerequisite is that you have updated your 15 installation to 15 Fix Pack 1. Please refer to IBM Modeler 15.0 Fix Pack 1 - Professional Components for additional details.

CONCLUSION:
The fix for this APAR is currently targeted for inclusion IBM SPSS Modeler 15.0 Fix Pack 2.

Installation Instructions

For All Platforms:
1) Ensure there are no users connected to IBM SPSS Modeler and stop the application

2) Unzip the Interim Fix into a temporary folder

3) To make a back up, move the original version of each file being replaced in step 4 to a temporary folder outside of the product installation folder [INSTALLDIR].

4) Move the files from the Interim Fix extracted in step 2 to:

- /lib/uiclient.jar should be placed in the [INSTALLDIR]/lib folder (Modeler Client only)

- all the files in /ext/bin/pasw.xmldata should be placed in the [INSTALLDIR]/ext/bin/pasw.xmldata

- xmldata.2.cfe (14.2) and xmldata.7.cfe (15.0) should be replaced in the [INSTALLDIR]/ext/lib folder

-all the files from /ext/lib/pasw.xmldata should be placed in the [INSTALLDIR]/ext/lib/pasw.xmldata folder

5) Restart the application

Download package


Download RELEASE DATE LANGUAGE SIZE(Bytes) Download Options
Modeler 14.2 FP3 IF15 AIX 28 Dec 2012 Language Independent 932785 HTTP
Modeler 14.2 FP3 IF15 HPUXIA 28 Dec 2012 Language Independent 1081321 HTTP
Modeler 14.2 FP3 IF15 Linux32 28 Dec 2012 Language Independent 654526 HTTP
Modeler 14.2 FP3 IF15 Linux64 28 Dec 2012 Language Independent 660556 HTTP
Modeler 14.2 FP3 IF15 Solaris 28 Dec 2012 Language Independent 643312 HTTP
Modeler 14.2 FP3 IF15 Win32 28 Dec 2012 Language Independent 11532430 HTTP
Modeler 14.2 FP3 IF15 Win64 28 Dec 2012 Language Independent 11547170 HTTP
Modeler 14.2 FP3 IF15 ZLin64 28 Dec 2012 Language Independent 598470 HTTP
Modeler 15.0 FP1 IF2 AIX 28 Dec 2012 Language Independent 810833 HTTP
Modeler 15.0 FP1 IF2 HPUXIA 28 Dec 2012 Language Independent 1115332 HTTP
Modeler 15.0 FP1 IF2 Lin32 28 Dec 2012 Language Independent 624007 HTTP
Modeler 15.0 FP1 IF2 Lin64 28 Dec 2012 Language Independent 624706 HTTP
Modeler 15.0 FP1 IF2 Solaris 28 Dec 2012 Language Independent 665276 HTTP
Modeler 15.0 FP1 IF2 Win32 28 Dec 2012 Language Independent 11964122 HTTP
Modeler 15.0 FP1 IF2 Win64 28 Dec 2012 Language Independent 11974742 HTTP
Modeler 15.0 FP1 IF2 zLin64 28 Dec 2012 Language Independent 625329 HTTP

Rate this page:

(0 users)Average rating

Document information


More support for:

SPSS Modeler

Software version:

Not Applicable

Operating system(s):

Platform Independent

Reference #:

4034122

Modified date:

2012-12-28

Translate my page

Machine Translation

Content navigation