CVE-2013-3998
published 2014-03-26CVE-2013-3998: CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
0.77%
51.4th percentile
CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM InfoSphere BigInsights prior 1.4.0.0 code injection (XFDB-84987 / BID-66359)
vuldb·2026-05-09·CVSS 3.5
CVE-2013-3998 [LOW] IBM InfoSphere BigInsights prior 1.4.0.0 code injection (XFDB-84987 / BID-66359)
A vulnerability classified as problematic has been found in IBM InfoSphere BigInsights. Affected by this issue is some unknown functionality. This manipulation causes code injection.
This vulnerability appears as CVE-2013-3998. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-8h4m-p2hq-jw7x: CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1
ghsa_unreviewed·2022-05-17
CVE-2013-3998 [LOW] CWE-94 GHSA-8h4m-p2hq-jw7x: CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1
CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-26
Published