VulnerabilityAnalyzed
CVE-2013-3993
IBM InfoSphere BigInsights Invalid Input Vulnerability
KEVMEDIUM 6.5EPSS 5.24%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 5.24% probability · 92th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
- Weakness
- CWE-22
- Affected
- ibm/infosphere biginsights
- Source
- psirt@us.ibm.com
CISA notes
The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2013-3993
References
- http://secunia.com/advisories/59676Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677445Vendor Advisory
- http://www.securityfocus.com/bid/68449Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84982Third Party Advisory, VDB Entry
- http://secunia.com/advisories/59676Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677445Vendor Advisory
- http://www.securityfocus.com/bid/68449Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84982Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3993US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.