7.5
CVE-2025-13723
- EPSS 0.02%
- Veröffentlicht 13.03.2026 18:32:45
- Zuletzt bearbeitet 18.03.2026 19:18:28
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling Partner Engagement Manager SwEditionessentials Version >= 6.2.3 < 6.2.3.6
Ibm ≫ Sterling Partner Engagement Manager SwEditionstandard Version >= 6.2.3 < 6.2.3.6
Ibm ≫ Sterling Partner Engagement Manager SwEditionessentials Version >= 6.2.4 < 6.2.4.3
Ibm ≫ Sterling Partner Engagement Manager SwEditionstandard Version >= 6.2.4 < 6.2.4.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.032 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@us.ibm.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-324 Use of a Key Past its Expiration Date
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.