CVE-2024-31896

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 327

Summary

CVE-2024-31896 is a vulnerability affecting IBM SPSS Statistics versions 26.0, 27.0.1, 28.0.1, and 29.0.2. The issue lies in the use of weaker than expected cryptographic algorithms, making it possible for attackers to decrypt highly sensitive information. This weakness in encryption could lead to unauthorized access to confidential data, posing a significant risk to organizations that rely on IBM SPSS Statistics for data analysis. Users are strongly advised to upgrade to a secure version as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM SPSS Statistics

Affected Vendors

  • IBM Corporation