EXPOSURES › CVE-2013-3993
CVE-2013-3993
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data.
The vulnerability in IBM InfoSphere BigInsights APIs allowed unauthorized data manipulation through invalid input, a flaw that was actively exploited in the wild and linked to ransomware attacks. DIB organizations must ensure their data analytics platforms are patched against known CVEs, as unpatched vulnerabilities in supply-chain components can lead to catastrophic data breaches and compliance failures under NIST 800-171. Organizations should verify that all software components, especially those handling sensitive data, are updated to the latest secure versions.
Shame score — A known vulnerability in a data analytics platform was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patch management and supply-chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
| PRODUCT | STATUS |
|---|---|
| IBM Cloud for Government IBM |
Authorized |
| IBM Federal HR Cloud IBM |
Authorized |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal IBM |
Authorized |
| MaaS360 Enterprise Mobility Management IBM |
Authorized |
| SmartCloud for Government IBM |
Authorized |