Sensitive Information Disclosure in IBM Sterling Partner Engagement Manager
CVE-2025-13718

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
13 March 2026

What is CVE-2025-13718?

The vulnerability identified in IBM Sterling Partner Engagement Manager versions 6.2.3.0 to 6.2.3.5 and 6.2.4.0 to 6.2.4.2 allows remote attackers to exploit a weakness in the communication channel, enabling them to intercept and retrieve sensitive information transmitted in cleartext. This poses a significant risk as unauthorized users can gain access to confidential data, potentially leading to further exploitation or data leaks. Organizations using the affected versions are advised to implement the recommended security patches and assess their communication configurations to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Sterling Partner Engagement Manager 6.2.3.0 <= 6.2.3.5

Sterling Partner Engagement Manager 6.2.4.0 <= 6.2.4.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.