Vulnerabilities > IBM > Partner Engagement Manager > High

DATE CVE VULNERABILITY TITLE RISK
2022-07-19 CVE-2022-22358 XXE vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2022-07-19 CVE-2022-22360 Injection vulnerability in IBM products
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection.
network
low complexity
ibm CWE-74
8.8
2022-04-01 CVE-2022-22331 Authorization Bypass Through User-Controlled Key vulnerability in IBM Partner Engagement Manager 6.2.0
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR).
network
low complexity
ibm CWE-639
7.1
2022-04-01 CVE-2022-22332 Operation on a Resource after Expiration or Release vulnerability in IBM Partner Engagement Manager 6.2.0
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token.
network
low complexity
ibm CWE-672
7.5