Vulnerabilities > CVE-2022-22331 - Authorization Bypass Through User-Controlled Key vulnerability in IBM Partner Engagement Manager 6.2.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
LOW Availability impact
NONE Summary
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |