CVE-2023-23481
published 2023-06-08CVE-2023-23481: IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary…
PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.37%
29.5th percentile
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sterling_partner_engagement_manager | — | — |
| ibm | sterling_partner_engagement_manager | >= 6.1.2 < 6.1.2.8 | 6.1.2.8 |
| ibm | sterling_partner_engagement_manager | >= 6.2.0 < 6.2.0.6 | 6.2.0.6 |
| ibm | sterling_partner_engagement_manager | >= 6.2.1 < 6.2.1.3 | 6.2.1.3 |
| neutrinolabs | xrdp | >= 0 < 0.6.0-1ubuntu0.1+esm3 | 0.6.0-1ubuntu0.1+esm3 |
| neutrinolabs | xrdp | >= 0 < 0.6.1-2ubuntu0.3+esm3 | 0.6.1-2ubuntu0.3+esm3 |
| neutrinolabs | xrdp | >= 0 < 0.9.5-2ubuntu0.1~esm2 | 0.9.5-2ubuntu0.1~esm2 |
| neutrinolabs | xrdp | >= 0 < 0.9.12-1ubuntu0.1+esm1 | 0.9.12-1ubuntu0.1+esm1 |
| neutrinolabs | xrdp | >= 0 < 0.9.17-2ubuntu2+esm1 | 0.9.17-2ubuntu2+esm1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
xrdp vulnerabilities
osv·2023-11-08·CVSS 9.8
CVE-2022-23479 xrdp vulnerabilities
xrdp vulnerabilities
It was discovered that xrdp incorrectly handled validation of
client-supplied data, which could lead to out-of-bounds reads. An attacker
could possibly use this issue to crash the program or extract sensitive
information. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,
CVE-2023-42822)
It was discovered that xrdp improperly handled session establishment
errors. An attacker could potentially use this issue to bypass the
OS-level session restrictions by PAM. (CVE-2023-40184)
It was discovered that xrdp incorrectly handled validation of
client-supplied data, which could lead to out-of-bounds writes. An attacker
could possibly use this issue to cause memory corruption or execute
arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04
GHSA
GHSA-v266-xq6j-4r2m: IBM Sterling Partner Engagement Manager 6
ghsa_unreviewed·2023-06-08
CVE-2023-23481 [MEDIUM] CWE-79 GHSA-v266-xq6j-4r2m: IBM Sterling Partner Engagement Manager 6
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-08
Published