First published: Wed Mar 16 2022(Updated: )
IBM Sterling Partner Engagement Manager could allow a malicious user to elevate their privileges and perform unintended operations to another users data.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Partner Engagement Manager | =6.2.0 | |
IBM SterlingPartner Engagement Manager Standard Edition | <=6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22328 is medium with a severity value of 6.2.
A malicious user can elevate their privileges and perform unintended operations to another user's data with CVE-2022-22328.
IBM Sterling Partner Engagement Manager version 6.2.0 is affected by CVE-2022-22328.
You can fix CVE-2022-22328 by applying the patch provided by IBM. Please refer to the following URL for the patch: [http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&fixids=IBM_PEM_Standard_6.2.0.2&source=SAR](http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&fixids=IBM_PEM_Standard_6.2.0.2&source=SAR)
More information about CVE-2022-22328 can be found on the IBM X-Force Exchange website: [https://exchange.xforce.ibmcloud.com/vulnerabilities/218871](https://exchange.xforce.ibmcloud.com/vulnerabilities/218871)