SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2013-3993

IBM InfoSphere BigInsights Invalid Input Vulnerability

KEVMEDIUM 6.5EPSS 5.24%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
5.24% probability · 92th percentile
CISA KEV
Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
Weakness
CWE-22
Affected
ibm/infosphere biginsights
Source
psirt@us.ibm.com

CISA notes

The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2013-3993

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.