First published: Wed Mar 16 2022(Updated: )
IBM Sterling Partner Engagement Manager could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR).
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Partner Engagement Manager | =6.2.0 | |
IBM Sterling Partner Engagement Manager Standard Edition | <=6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM Sterling Partner Engagement Manager vulnerability is CVE-2022-22331.
The severity level of CVE-2022-22331 is high with a CVSS score of 7.1.
An attacker can exploit this vulnerability by obtaining sensitive information or modifying user details.
The version 6.2.0 of IBM Sterling Partner Engagement Manager is affected by CVE-2022-22331.
To fix this vulnerability, apply the patch provided by IBM for version 6.2.0.2 of IBM Sterling Partner Engagement Manager.