CVE-2025-14811

CWE-5983 documents3 sources
Severity
5.9MEDIUM
EPSS
0.0%
top 92.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13

Description

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/sterling_partner_engagement_manager6.2.3.06.2.3.5+1

🔴Vulnerability Details

2
GHSA
GHSA-m2h3-rp3m-p73r: IBM Sterling Partner Engagement Manager 62026-03-13
CVEList
IBM Sterling Partner Engagement Manager Information Disclosure2026-03-13
CVE-2025-14811 (MEDIUM CVSS 5.9) | IBM Sterling Partner Engagement Man | cvebase.io