User Impersonation Vulnerability in IBM Sterling Partner Engagement Manager
CVE-2022-22332
5.6MEDIUM
What is CVE-2022-22332?
The IBM Sterling Partner Engagement Manager 6.2.0 is vulnerable to a user impersonation issue, allowing attackers to bypass authentication mechanisms. This vulnerability stems from a missing revocation process for JSON Web Tokens (JWT), which could let unauthorized users assume the identity of legitimate accounts, thus compromising sensitive data and potentially leading to unauthorized actions within the system. Organizations utilizing this product should implement necessary measures to mitigate risk.
Affected Version(s)
Sterling Partner Engagement Manager 6.2.0