CVE-2013-6321
Summary
| CVE | CVE-2013-6321 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-10 12:02:51 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS: 0.003670000 probability, percentile 0.586240000 (date 2026-05-01)
Problem Types: CWE-89 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Atlas Ediscovery Process Management | 6.0.2 | All | All | All |
| Application | Ibm | Atlas Ediscovery Process Management | All | All | All | All |
| Application | Ibm | Atlas Suite | - | All | All | All |
| Application | Ibm | Disposal And Governance Management For It | 6.0.2 | All | All | All |
| Application | Ibm | Disposal And Governance Management For It | All | All | All | All |
| Application | Ibm | Global Retention Policy And Schedule Management | 6.0.2 | All | All | All |
| Application | Ibm | Global Retention Policy And Schedule Management | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/101856 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM Blogs | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| Multiple IBM Products CVE-2013-6321 Unspecified SQL Injection Vulnerabilitiy | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.