7.5

CVE-2023-43045

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication.  IBM X-Force ID:  266896.

Data is provided by the National Vulnerability Database (NVD)
IbmSterling Partner Engagement Manager Version6.1.2 SwEditionessentials
IbmSterling Partner Engagement Manager Version6.1.2 SwEditionstandard
IbmSterling Partner Engagement Manager Version6.2.0 SwEditionessentials
IbmSterling Partner Engagement Manager Version6.2.0 SwEditionstandard
IbmSterling Partner Engagement Manager Version6.2.2 SwEditionessentials
IbmSterling Partner Engagement Manager Version6.2.2 SwEditionstandard
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.07
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
psirt@us.ibm.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.