Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2023-28517

Disclosure Date: March 13, 2024 (last updated January 23, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250421.
Attacker Value
Unknown

CVE-2023-43045

Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.
Attacker Value
Unknown

CVE-2023-38722

Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.
Attacker Value
Unknown

CVE-2022-40615

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.
Attacker Value
Unknown

CVE-2022-34335

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
Attacker Value
Unknown

CVE-2022-34354

Disclosure Date: November 16, 2022 (last updated November 08, 2023)
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.
Attacker Value
Unknown

CVE-2022-22328

Disclosure Date: March 31, 2022 (last updated October 07, 2023)
IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871.
Attacker Value
Unknown

CVE-2022-22332

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.
Attacker Value
Unknown

CVE-2022-22331

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.