CVE-2025-13882: Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.
IBM Sterling Partner Engagement Manager could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency
Other sources
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling Partner Engagement Manager Essentials Editionto a version that resolves this vulnerability.Fixed in 6.3.0.3 - Upgrade
Upgrade
IBM Sterling Partner Engagement Manager Essentials Editionto a version that resolves this vulnerability.Fixed in 6.2.4.5 - Upgrade
Upgrade
IBM Sterling Partner Engagement Manager Standard Editionto a version that resolves this vulnerability.Fixed in 6.2.4.5
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2 and 6.2.4.0 through 6.2.4.4, plus Standard Edition 6.2.4.0 through 6.2.4.4.
Does exploitation require authentication or user interaction?
No. The issue can be exploited by an unauthenticated user and does not require user interaction.
What is the likely impact of exploitation?
An attacker can cause a denial of service affecting the email service. The provided impact metrics indicate availability impact only, with no stated confidentiality or integrity impact.