peter bassill · operator
$ cve CVE-2013-3993 JSON

CVE-2013-3993 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 4.8% (pctl 92)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-15.

Description

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS4.77% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-06-15
Public exploitnone known
Published2014-07-07
Last modified2026-06-16

CISA KEV

NameIBM InfoSphere BigInsights Invalid Input Vulnerability
Added2022-05-25
Due2022-06-15
Vendor / productIBM / InfoSphere BigInsights
Ransomware useknown

Affected (1)

VendorProduct
ibminfosphere biginsights

References

→ the Explorer  ·  watch your stack  ·  NVD