LDAP Injection Vulnerability in IBM Sterling Partner Engagement Manager
CVE-2022-22360
7.5HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 19 July 2022
Summary
A vulnerability in IBM Sterling Partner Engagement Manager allows remote authenticated attackers to perform LDAP injection. By crafting specific requests, attackers can manipulate LDAP queries, potentially gaining unauthorized access to sensitive resources. Affected versions include 6.1.2, 6.2, and Cloud/SaaS 22.2 platforms. Organizations utilizing these versions should assess their security posture and implement necessary mitigations.
Affected Version(s)
Sterling Partner Engagement Manager 6.1.2
Sterling Partner Engagement Manager 6.2
Sterling Partner Engagement Manager on Cloud 22.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved