Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Partner_engagement_manager
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 10 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-07-30 | CVE-2021-29781 | IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 203091. | Partner_engagement_manager | 9.8 | ||
2022-04-01 | CVE-2022-22328 | IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871. | Partner_engagement_manager | 6.2 | ||
2022-04-01 | CVE-2022-22331 | IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130. | Partner_engagement_manager | 7.1 | ||
2022-04-01 | CVE-2022-22332 | IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131. | Partner_engagement_manager | 7.5 | ||
2022-07-19 | CVE-2022-22358 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651. | Partner_engagement_manager, Partner_engagement_manager_on_cloud\/saas | 7.1 | ||
2022-07-19 | CVE-2022-22359 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652. | Partner_engagement_manager, Partner_engagement_manager_on_cloud\/saas | 6.5 | ||
2022-07-19 | CVE-2022-22360 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782. | Partner_engagement_manager, Partner_engagement_manager_on_cloud\/saas | 8.8 | ||
2022-07-19 | CVE-2022-22416 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126. | Partner_engagement_manager, Partner_engagement_manager_on_cloud\/saas | 5.4 | ||
2022-07-19 | CVE-2022-22417 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223127. | Partner_engagement_manager, Partner_engagement_manager_on_cloud\/saas | 5.4 | ||
2022-11-16 | CVE-2022-34354 | IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424. | Partner_engagement_manager | 3.3 |