Skip to content
COOEY

EXPOSURES › CVE-2013-3993

CVE-2013-3993

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-3993 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

IBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data.

The vulnerability in IBM InfoSphere BigInsights APIs allowed unauthorized data manipulation through invalid input, a flaw that was actively exploited in the wild and linked to ransomware attacks. DIB organizations must ensure their data analytics platforms are patched against known CVEs, as unpatched vulnerabilities in supply-chain components can lead to catastrophic data breaches and compliance failures under NIST 800-171. Organizations should verify that all software components, especially those handling sensitive data, are updated to the latest secure versions.

Shame score — A known vulnerability in a data analytics platform was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patch management and supply-chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

AFFECTED FEDRAMP PRODUCTS · 5
PRODUCTSTATUS
IBM Cloud for Government
IBM
Authorized
IBM Federal HR Cloud
IBM
Authorized
IBM Maximo and TRIRIGA on Cloud for U.S. Federal
IBM
Authorized
MaaS360 Enterprise Mobility Management
IBM
Authorized
SmartCloud for Government
IBM
Authorized