cbcvebase.
CVE-2013-3993
published 2014-07-07

CVE-2013-3993: IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or…

PriorityP182medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
5.24%
91.6th percentile
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

Affected

1 ranges
VendorProductVersion rangeFixed in
ibminfosphere_biginsights< 2.1.0.32.1.0.3

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2013-3993 involves crafted/invalid parameters in API calls to IBM InfoSphere BigInsights; monitor for anomalous or malformed API requests targeting BigInsights endpoints, particularly those attempting unauthorized read, write, modify, or delete operations on data.
  • The attack vector is remote authenticated exploitation via crafted API parameters; audit authentication logs on BigInsights for authenticated users making unusual or unexpected API calls that bypass file/directory restrictions.
  • ·IBM InfoSphere BigInsights is end-of-life; CISA mandates disconnection rather than patching. Any instance still in use should be treated as critically exposed.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.