CVE-2013-6334
Estado: ModificadaMedia (6.4)—
IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows remote attackers to bypass intended access restrictions, and visit PolicyAtlas/ResponseDraftServlet (aka the Compliance Questionnaire Save Draft servlet), via unspecified vectors.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.36%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-20
Referencias
- http://osvdb.org/show/osvdb/101855
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_atlas_suite_atlas_policy_suite_sql_injection_vulnerability_cve_2013_6321_and_access_control_vulnerability_cve_2013_6334
- http://www.securityfocus.com/bid/64751
- http://osvdb.org/show/osvdb/101855
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_atlas_suite_atlas_policy_suite_sql_injection_vulnerability_cve_2013_6321_and_access_control_vulnerability_cve_2013_6334
- http://www.securityfocus.com/bid/64751
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-6334",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-01-10T12:02:51.543",
"references": [
{
"url": "http://osvdb.org/show/osvdb/101855",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_atlas_suite_atlas_policy_suite_sql_injection_vulnerability_cve_2013_6321_and_access_control_vulnerability_cve_2013_6334",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/bid/64751",
"source": "psirt@us.ibm.com"
},
{
"url": "http://osvdb.org/show/osvdb/101855",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_atlas_suite_atlas_policy_suite_sql_injection_vulnerability_cve_2013_6321_and_access_control_vulnerability_cve_2013_6334",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/64751",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows remote attackers to bypass intended access restrictions, and visit PolicyAtlas/ResponseDraftServlet (aka the Compliance Questionnaire Save Draft servlet), via unspecified vectors."
},
{
"lang": "es",
"value": "IBM Atlas eDiscovery Process Management 6.0.1.5 y anteriores versiones y 6.0.2, Disposal and Governance Management for IT 6.0.1.5 y anteriores y 6.0.2, y Global Retention Policy y Schedule Management 6.0.1.5 y anteriores versiones y 6.0.2 en IBM Atlas Suite (también conocido como Atlas Policy Suite) no valida adecuadamente las sesiones, lo que permite a atacantes remotos evadir restricciones de acceso intencionadas, y visitar PolicyAtlas/ResponseDraftServlet (también conocido como servlet Compliance Questionnaire Save Draft), a través de vectores sin especificar."
}
],
"lastModified": "2026-06-17T00:00:18.770",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:atlas_ediscovery_process_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A91B299-5218-4A60-97D3-3FD7E73E6CD4",
"versionEndIncluding": "6.0.1.5"
},
{
"criteria": "cpe:2.3:a:ibm:atlas_ediscovery_process_management:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E89916C9-0EA1-43D9-93AA-2DF395A8C491"
},
{
"criteria": "cpe:2.3:a:ibm:atlas_suite:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD5284A0-04C8-4E0D-83CF-4BB7D42E53E8"
},
{
"criteria": "cpe:2.3:a:ibm:disposal_and_governance_management_for_it:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4275BE22-CE0F-4F66-9723-D18FC3E68130",
"versionEndIncluding": "6.0.1.5"
},
{
"criteria": "cpe:2.3:a:ibm:disposal_and_governance_management_for_it:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0BF4D8C-3619-4668-93A9-9B1DADD875B9"
},
{
"criteria": "cpe:2.3:a:ibm:global_retention_policy_and_schedule_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "712DE98D-5713-44EE-BEFE-8A4F7FB648DD",
"versionEndIncluding": "6.0.1.5"
},
{
"criteria": "cpe:2.3:a:ibm:global_retention_policy_and_schedule_management:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46246951-8F50-40E8-8AEC-0773C48E8A54"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}