CVE-2022-34354

CWE-9223 documents3 sources
Severity
3.3LOW
EPSS
0.0%
top 87.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16

Description

IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.5 | Impact: 1.4

Affected Packages2 packages

NVDibm/partner_engagement_manager6.1.2, 6.2.0, 6.2.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vg7q-fc44-5hp4: IBM Sterling Partner Engagement Manager 22022-11-16
CVEList
IBM Sterling Partner Engagement Manager information disclosure2022-11-16