cbcvebase.

Ibm Sterling Partner Engagement Manager vulnerabilities

24 known vulnerabilities affecting ibm/sterling_partner_engagement_manager.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM12

Vulnerabilities

Page 2 of 2
CVE-2023-38722P4MEDIUMCVSS 5.4v6.1.2v6.2.0+2 more2023-10-23
CVE-2023-38722 [MEDIUM] CWE-79 CVE-2023-38722: IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site s IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.
nvd
CVE-2023-28517P4MEDIUMCVSS 5.4v6.1.2v6.2.0+2 more2024-03-13
CVE-2023-28517 [MEDIUM] CWE-79 CVE-2023-28517: IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scriptin IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250421.
nvd
CVE-2023-23480P4MEDIUMCVSS 5.4≥ 6.1.2, < 6.1.2.8≥ 6.2.0, < 6.2.0.6+2 more2023-06-08
CVE-2023-23480 [MEDIUM] CWE-79 CVE-2023-23480: IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. T IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245885.
nvd
CVE-2022-35640P4MEDIUMCVSS 5.5v6.2.22024-07-16
CVE-2022-35640 [MEDIUM] CWE-209 CVE-2022-35640: IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive infor IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is returned. IBM X-Force ID: 230933.
nvd