CVE-2013-3993: IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
Other sources
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If IBM InfoSphere BigInsights (before 2.1.0.3) is still in use, disconnect it from the network because the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3993?
CVE-2013-3993 is categorized as a moderate severity vulnerability.
How do I fix CVE-2013-3993?
To mitigate the effects of CVE-2013-3993, upgrade IBM InfoSphere BigInsights to version 2.1.0.3 or later.
Who is affected by CVE-2013-3993?
CVE-2013-3993 affects all versions of IBM InfoSphere BigInsights prior to 2.1.0.3, as well as specific earlier versions like 1.1.0.0 to 1.4.0.0.
What kind of access does CVE-2013-3993 allow to an attacker?
CVE-2013-3993 allows remote authenticated users to bypass intended file and directory restrictions.
What are the potential impacts of CVE-2013-3993?
The potential impacts of CVE-2013-3993 include unauthorized access to untrusted data or code within the IBM InfoSphere BigInsights environment.