IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM — InfoSphere BigInsights
- Added to KEV catalog
- 25 May 2022
- Federal remediation due date
- 15 June 2022
- Weakness classification (CWE)
- CWE-264
CISA Description
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2013-3993
More IBM Vulnerabilities
IBM Langflow Code Injection Vulnerability
IBM Aspera Faspex Code Execution Vulnerability
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
IBM Data Risk Manager Directory Traversal Vulnerability
IBM Data Risk Manager Remote Code Execution Vulnerability
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services