LDAP Injection Vulnerability in IBM Sterling Partner Engagement Manager
CVE-2022-22360

7.5HIGH

Key Information:

Summary

A vulnerability in IBM Sterling Partner Engagement Manager allows remote authenticated attackers to perform LDAP injection. By crafting specific requests, attackers can manipulate LDAP queries, potentially gaining unauthorized access to sensitive resources. Affected versions include 6.1.2, 6.2, and Cloud/SaaS 22.2 platforms. Organizations utilizing these versions should assess their security posture and implement necessary mitigations.

Affected Version(s)

Sterling Partner Engagement Manager 6.1.2

Sterling Partner Engagement Manager 6.2

Sterling Partner Engagement Manager on Cloud 22.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.