First published: Wed Mar 16 2022(Updated: )
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Partner Engagement Manager | =6.2.0 | |
IBM Sterling Partner Engagement Manager Standard Edition | <=6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-22332.
The severity of CVE-2022-22332 is high with a CVSS score of 7.5.
CVE-2022-22332 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token in IBM Sterling Partner Engagement Manager 6.2.0.
IBM Sterling Partner Engagement Manager 6.2.0 is affected by CVE-2022-22332.
To fix CVE-2022-22332, you should apply the patch provided by IBM. Please refer to the IBM Support page for more information.