Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2022-35640
Disclosure Date: July 16, 2024 (last updated October 19, 2024)
IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is returned. IBM X-Force ID: 230933.
0
Attacker Value
Unknown
CVE-2023-28517
Disclosure Date: March 13, 2024 (last updated January 23, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250421.
0
Attacker Value
Unknown
CVE-2023-43045
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.
0
Attacker Value
Unknown
CVE-2023-38722
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.
0
Attacker Value
Unknown
CVE-2023-23482
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 245891.
0
Attacker Value
Unknown
CVE-2023-23481
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889.
0
Attacker Value
Unknown
CVE-2023-23480
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245885.
0
Attacker Value
Unknown
CVE-2022-40615
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.
0
Attacker Value
Unknown
CVE-2022-34335
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
0
Attacker Value
Unknown
CVE-2022-34334
Disclosure Date: October 08, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.
0