Ibm Sterling Partner Engagement Manager vulnerabilities

24 known vulnerabilities affecting ibm/sterling_partner_engagement_manager.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM12

Vulnerabilities

Page 2 of 2
CVE-2022-22359MEDIUMCVSS 6.5v6.1.2v6.22022-07-19
CVE-2022-22359 [MEDIUM] CWE-352 CVE-2022-22359: IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.
cvelistv5nvd
CVE-2022-22417MEDIUMCVSS 5.4v6.1.2v6.22022-07-19
CVE-2022-22417 [MEDIUM] CWE-79 CVE-2022-22417: IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223127.
cvelistv5nvd
CVE-2022-22416MEDIUMCVSS 5.4v6.1.2v6.22022-07-19
CVE-2022-22416 [MEDIUM] CWE-918 CVE-2022-22416: IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126.
cvelistv5nvd
CVE-2022-22332HIGHCVSS 7.5v6.2.02022-04-01
CVE-2022-22332 [HIGH] CWE-672 CVE-2022-22332: IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user du IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.
cvelistv5nvd