IBM Sterling Partner Engagement Manager 6.2.1 Standard Edition

CPE Details

IBM Sterling Partner Engagement Manager 6.2.1 Standard Edition
6.2.1
2023-01-17
22h59 +00:00
2023-02-28
20h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:sterling_partner_engagement_manager:6.2.1:*:*:*:standard:*:*:*

Informations

Vendor

ibm

Product

sterling_partner_engagement_manager

Version

6.2.1

Software Edition

standard

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-23480 2023-06-08 01h42 +00:00 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245885.
5.4
Medium
CVE-2023-23481 2023-06-08 01h29 +00:00 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889.
6.4
Medium
CVE-2023-23482 2023-06-08 01h09 +00:00 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 245891.
9.6
Critical
CVE-2022-40615 2023-01-11 16h48 +00:00 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.
9.8
Critical
CVE-2022-34335 2023-01-11 16h42 +00:00 IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
6.5
Medium