First published: Mon Jan 09 2023(Updated: )
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling Partner Engagement Manager | =6.1.2 | |
IBM Sterling Partner Engagement Manager | =6.2.0 | |
IBM Sterling Partner Engagement Manager | =6.2.1 | |
Linux Linux kernel | ||
IBM Sterling Partner Engagement Manager Standard | <=6.1.2, 6.2.0, 6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34335 is a vulnerability in IBM Sterling Partner Engagement Manager that could allow an authenticated user to exhaust server resources, leading to a denial of service.
IBM Sterling Partner Engagement Manager versions 6.1.2, 6.2.0, and 6.2.1 are affected by CVE-2022-34335.
CVE-2022-34335 has a severity level of medium (CVSS v3.1 base score: 6.5).
An authenticated user can exploit CVE-2022-34335 by performing actions that exhaust server resources, such as sending a large number of requests.
Yes, IBM has released fixes and mitigations for CVE-2022-34335. Please refer to the IBM support page for more information.