First published: Tue Jun 21 2022(Updated: )
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Partner Engagement Manager | >=6.1.2<6.1.2.5 | |
IBM Partner Engagement Manager | >=6.1.2<6.1.2.5 | |
IBM Partner Engagement Manager | >=6.2.0<6.2.0.3 | |
IBM Partner Engagement Manager | >=6.2.0<6.2.0.3 | |
Ibm Partner Engagement Manager On Cloud\/saas | =22.2 | |
<=6.1.2 | ||
<=6.1.2 | ||
<=6.2 | ||
<=6.2 | ||
<=22.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22359 is medium with a severity value of 6.5.
IBM Sterling Partner Engagement Manager versions 6.1.2, 6.2, and Cloud/SaaS 22.2 are affected by CVE-2022-22359.
Cross-site request forgery is a type of web vulnerability where an attacker tricks a user into unknowingly performing unwanted actions on a trusted website.
An attacker can exploit CVE-2022-22359 by executing malicious and unauthorized actions through cross-site request forgery.
You can fix the vulnerability CVE-2022-22359 by applying the necessary patches provided by IBM.