CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CISA KEV Details
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Known
Added to KEV: 2022-05-25
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Original NVD Description
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.