CVE-2013-3993 KEV
6.5
MEDIUM · CVSS 3.1 · EPSS 4.8% (pctl 92)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-15.
Description
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 4.77% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2022-06-15 |
| Public exploit | none known |
| Published | 2014-07-07 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | IBM InfoSphere BigInsights Invalid Input Vulnerability |
|---|---|
| Added | 2022-05-25 |
| Due | 2022-06-15 |
| Vendor / product | IBM / InfoSphere BigInsights |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | infosphere biginsights |
References
- http://secunia.com/advisories/59676
- http://www-01.ibm.com/support/docview.wss?uid=swg21677445
- http://www.securityfocus.com/bid/68449
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84982
- http://secunia.com/advisories/59676
- http://www-01.ibm.com/support/docview.wss?uid=swg21677445
- http://www.securityfocus.com/bid/68449
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84982
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3993
→ the Explorer · watch your stack · NVD