Vulnerabilities > IBM > Partner Engagement Manager

DATE CVE VULNERABILITY TITLE RISK
2022-11-16 CVE-2022-34354 Insecure Storage of Sensitive Information vulnerability in IBM Partner Engagement Manager 6.1.2/6.2.0/6.2.1
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2022-07-19 CVE-2022-22358 XXE vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2022-07-19 CVE-2022-22359 Cross-Site Request Forgery (CSRF) vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
6.5
2022-07-19 CVE-2022-22360 Injection vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection.
network
low complexity
ibm CWE-74
8.8
2022-07-19 CVE-2022-22416 Server-Side Request Forgery (SSRF) vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
5.4
2022-07-19 CVE-2022-22417 Cross-site Scripting vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-04-01 CVE-2022-22328 Unspecified vulnerability in IBM Partner Engagement Manager 6.2.0
IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data.
local
low complexity
ibm
6.2
2022-04-01 CVE-2022-22331 Authorization Bypass Through User-Controlled Key vulnerability in IBM Partner Engagement Manager 6.2.0
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR).
network
low complexity
ibm CWE-639
7.1
2022-04-01 CVE-2022-22332 Operation on a Resource after Expiration or Release vulnerability in IBM Partner Engagement Manager 6.2.0
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token.
network
low complexity
ibm CWE-672
7.5
2021-07-30 CVE-2021-29781 Deserialization of Untrusted Data vulnerability in IBM Partner Engagement Manager 2.0
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw.
network
low complexity
ibm CWE-502
critical
9.8