Cross-Site Scripting Vulnerability in IBM Sterling Partner Engagement Manager
CVE-2025-13702
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 13 March 2026
What is CVE-2025-13702?
IBM Sterling Partner Engagement Manager versions 6.2.3.0 to 6.2.3.5 and 6.2.4.0 to 6.2.4.2 exhibit a cross-site scripting vulnerability. This allows an authenticated user to inject arbitrary JavaScript code into the Web UI, potentially compromising user credentials and altering application functionality within a trusted session. Organizations using these affected versions should apply the appropriate patches to secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Sterling Partner Engagement Manager 6.2.3.0 <= 6.2.3.5
Sterling Partner Engagement Manager 6.2.4.0 <= 6.2.4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved