• Description
  • Problem summary

Is Statistics vulnerable to CVE-2025-8194

  • Problem conclusion

This issue has been reported to IBM SPSS Statistics Development and will be addressed in a future release.

  • Temporary workaround

Strictly speaking, this is not an IBM SPSS Statistics vulnerability, but rather a vulnerability in the version of Python3 shipped with IBM SPSS Statistics. Ultimately, this CVE must be resolved by python.org.

IBM SPSS Statistics is capable of using an external Python3 instead of the shipped Python3.

  • External Python3.png

     



    In this case, CVE-2025-8194 has been resolved for:

      • Python 3.10.19 (IBM SPSS Statistics 31.0.x.x)
      • Python 3.13.6 (IBM SPSS Statistics 32.0.0.0)

    Please install one of these external Python3 instances, as appropriate for your installation of IBM SPSS Statistics, and have the application use that Python3 instance instead of the shipped instance.