CVE-2013-3993
published 2014-07-07CVE-2013-3993: IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or…
PriorityP182medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
5.24%
91.6th percentile
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | infosphere_biginsights | < 2.1.0.3 | 2.1.0.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2013-3993 involves crafted/invalid parameters in API calls to IBM InfoSphere BigInsights; monitor for anomalous or malformed API requests targeting BigInsights endpoints, particularly those attempting unauthorized read, write, modify, or delete operations on data. ↗
- →The attack vector is remote authenticated exploitation via crafted API parameters; audit authentication logs on BigInsights for authenticated users making unusual or unexpected API calls that bypass file/directory restrictions. ↗
- ·IBM InfoSphere BigInsights is end-of-life; CISA mandates disconnection rather than patching. Any instance still in use should be treated as critically exposed. ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qh2-hj3f-rhcf: IBM InfoSphere BigInsights before 2
ghsa_unreviewed·2022-05-17
CVE-2013-3993 [LOW] CWE-22 GHSA-2qh2-hj3f-rhcf: IBM InfoSphere BigInsights before 2
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
VulnCheck
IBM InfoSphere BigInsights Invalid Input Vulnerability
vulncheck·2013·CVSS 6.5
CVE-2013-3993 [MEDIUM] CWE-264 IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM InfoSphere BigInsights Invalid Input Vulnerability
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
Affected: IBM InfoSphere BigInsights
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://cybersecurityworks.com/howdymanage/uploads/file/ransomware-_-2022-spotlight-report_compressed.pdf; https://cybersecurityworks.com/howdymanage/uploads/file/RansomwareUpdate%20Report%202022%20Q1.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.ivanti.com/resources/v/doc/pr-survey-report/ransomware-quarterly-indexreport_q2-q3; https://info.se
CISA
IBM InfoSphere BigInsights Invalid Input Vulnerability
cisa·2022-05-25·CVSS 6.5
CVE-2013-3993 [MEDIUM] CWE-264 IBM InfoSphere BigInsights Invalid Input Vulnerability
Vulnerability: IBM InfoSphere BigInsights Invalid Input Vulnerability
Affected: IBM InfoSphere BigInsights
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3993
Remediation Due Date: 2022-06-15
Suricata
ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt
suricata·2015-05-08·CVSS 9.3
CVE-2013-1710 [CRITICAL] ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt
ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt"; flow:established,to_client; file.data; content:"generateCRMFRequest"; nocase; fast_pattern; content:"InstallTrigger"; nocase; content:"__exposedProps__"; nocase; content:"__defineGetter__"; nocase; content:"getInstallForURL"; nocase; content:".install|28|"; nocase; content:"x-xpinstall"; nocase; reference:cve,CVE-2013-1710; reference:cve,CVE-2012-3993; classtype:attempted-user; sid:2021078; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2015_05_08, deployment Perimeter, confidence Medium, signature_sever
No public exploits indexed.
http://secunia.com/advisories/59676http://www-01.ibm.com/support/docview.wss?uid=swg21677445http://www.securityfocus.com/bid/68449https://exchange.xforce.ibmcloud.com/vulnerabilities/84982http://secunia.com/advisories/59676http://www-01.ibm.com/support/docview.wss?uid=swg21677445http://www.securityfocus.com/bid/68449https://exchange.xforce.ibmcloud.com/vulnerabilities/84982https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3993
2014-07-07
Published
2022-05-25
Added to CISA KEV
Exploited in the wild