4
CVE-2022-34354
- EPSS 0.04%
- Veröffentlicht 16.11.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:09:20
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Sterling Partner Engagement Manager information disclosure
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Partner Engagement Manager Version6.1.2 SwEditionstandard
Ibm ≫ Partner Engagement Manager Version6.2.0 SwEditionstandard
Ibm ≫ Partner Engagement Manager Version6.2.1 SwEditionstandard
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.124 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| psirt@us.ibm.com | 4 | 2.5 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.