First published: Thu Sep 22 2022(Updated: )
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Partner Engagement Manager | <=2.0 | |
IBM Sterling Partner Engagement Manager | >=2.0<6.1.2.6 | |
IBM Sterling Partner Engagement Manager | >=2.0<6.1.2.6 | |
IBM Sterling Partner Engagement Manager | >=6.2.0.0<6.2.0.4 | |
IBM Sterling Partner Engagement Manager | >=6.2.0.0<6.2.0.4 | |
IBM Sterling Partner Engagement Manager | =6.2.1.0 | |
IBM Sterling Partner Engagement Manager | =6.2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34348 is a vulnerability in IBM Sterling Partner Engagement Manager 6.1 that allows XML External Entity Injection (XXE) attacks, leading to potential exposure of sensitive information or memory resource consumption.
CVE-2022-34348 can be exploited by remote attackers to perform XML External Entity Injection (XXE) attacks on IBM Sterling Partner Engagement Manager, potentially resulting in the exposure of sensitive information or memory resource consumption.
The severity of CVE-2022-34348 is high, with a CVSS score of 7.1.
To fix CVE-2022-34348, IBM Sterling Partner Engagement Manager users should apply the necessary security updates provided by IBM and follow best practices for secure XML processing.
You can find more information about CVE-2022-34348 on the IBM Security Advisory page and the IBM X-Force Exchange website.