Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows remote attackers to bypass intended access restrictions, and visit PolicyAtlas/ResponseDraftServlet (aka the Compliance Questionnaire Save Draft servlet), via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款IBM Atlas Suite产品输入验证漏洞
Vulnerability Description
IBM Atlas eDiscovery Process Management等都是美国IBM公司的信息生命周期治理解决方案中的产品,该方案能够跨信息生命周期治理内容,包括归档、防御性处理(defensible disposal)、记录和eDiscovery。 IBM Atlas Suite (又名Atlas Policy Suite)中存在输入验证漏洞,该漏洞源于程序没有正确验证会话。远程攻击者可利用该漏洞绕过既定的访问限制,进而访问PolicyAtlas/ResponseDraftServlet应用程
CVSS Information
N/A
Vulnerability Type
N/A