7.5
CVE-2025-13723
- EPSS 0.02%
- Veröffentlicht 13.03.2026 18:32:45
- Zuletzt bearbeitet 18.03.2026 19:18:28
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Sterling Partner Engagement Manager Information Disclosure
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling Partner Engagement Manager SwEditionessentials Version >= 6.2.3 < 6.2.3.6
Ibm ≫ Sterling Partner Engagement Manager SwEditionstandard Version >= 6.2.3 < 6.2.3.6
Ibm ≫ Sterling Partner Engagement Manager SwEditionessentials Version >= 6.2.4 < 6.2.4.3
Ibm ≫ Sterling Partner Engagement Manager SwEditionstandard Version >= 6.2.4 < 6.2.4.3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.041 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@us.ibm.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-324 Use of a Key Past its Expiration Date
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.