First published: Fri Oct 07 2022(Updated: )
IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling Partner Engagement Manager | <=2.0 | |
IBM Sterling Partner Engagement Manager | =2.0 | |
IBM Sterling Partner Engagement Manager | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-34334.
The title of this vulnerability is 'IBM Sterling Partner Engagement Manager does not invalidate session after logout which could allow a…'
The severity of CVE-2022-34334 is medium.
CVE-2022-34334 affects IBM Sterling Partner Engagement Manager version 2.0.
Yes, a patch is available for CVE-2022-34334. You can download it from [IBM Fix Central](http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&fixids=IBM_PEM_Essentials_6.2.0.4&source=SAR).