Privilege Escalation in IBM Sterling Partner Engagement Manager
CVE-2022-22328

6.2MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 April 2022

Summary

IBM Sterling Partner Engagement Manager version 6.2.0 contains a vulnerability that could allow unauthorized users to escalate their privileges, potentially granting them access to perform unintended operations on the data of other users. This significant flaw can be exploited by malicious actors to manipulate sensitive user information, compromising the integrity and confidentiality of the system.

Affected Version(s)

SterlingPartner Engagement Manager 6.2.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.