CVE-2013-3993

IBM InfoSphere BigInsights: Invalid Input

As of , CVE-2013-3993 in IBM InfoSphere BigInsights is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 25 May 2022
US federal deadline
15 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.05Higher than 91% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 25 May 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

The impacted product is end-of-life and should be disconnected if still in use.

CISA's required action

What the flaw is

Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

CISA's description

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

The CVE record's description, from ibm

CVE published
7 July 2014
Assigned by
ibm
CVSS
6.5 Medium (CVSS 3.1, from CISA-ADP)
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-264
Permissions, Privileges, and Access Controls
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Read further