CVE-2013-3993
בינונית 6.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- IBM InfoSphere BigInsights Invalid Input Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-22
מוצרים מושפעים
ibm: infosphere biginsights
קישורים
- http://www-01.ibm.com/support/docview.wss?uid=swg21677445 Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21677445 Vendor Advisory
- http://secunia.com/advisories/59676 Broken Link
- http://www.securityfocus.com/bid/68449 Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84982 Third Party AdvisoryVDB Entry
- http://secunia.com/advisories/59676 Broken Link
- http://www.securityfocus.com/bid/68449 Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84982 Third Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource