CVE-2013-6334
Summary
| CVE | CVE-2013-6334 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-10 12:02:51 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows remote attackers to bypass intended access restrictions, and visit PolicyAtlas/ResponseDraftServlet (aka the Compliance Questionnaire Save Draft servlet), via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS: 0.001810000 probability, percentile 0.393920000 (date 2026-05-01)
Problem Types: CWE-20 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Atlas Ediscovery Process Management | 6.0.2 | All | All | All |
| Application | Ibm | Atlas Ediscovery Process Management | All | All | All | All |
| Application | Ibm | Atlas Suite | - | All | All | All |
| Application | Ibm | Disposal And Governance Management For It | 6.0.2 | All | All | All |
| Application | Ibm | Disposal And Governance Management For It | All | All | All | All |
| Application | Ibm | Global Retention Policy And Schedule Management | 6.0.2 | All | All | All |
| Application | Ibm | Global Retention Policy And Schedule Management | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Blogs | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| Multiple IBM Products 'Save Draft' Access Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/show/osvdb/101855 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.