7.5
CVE-2025-13726
- EPSS 0.05%
- Veröffentlicht 13.03.2026 18:26:34
- Zuletzt bearbeitet 18.03.2026 20:28:22
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling Partner Engagement Manager SwEditionessentials Version >= 6.2.3 < 6.2.3.6
Ibm ≫ Sterling Partner Engagement Manager SwEditionstandard Version >= 6.2.3 < 6.2.3.6
Ibm ≫ Sterling Partner Engagement Manager SwEditionessentials Version >= 6.2.4 < 6.2.4.3
Ibm ≫ Sterling Partner Engagement Manager SwEditionstandard Version >= 6.2.4 < 6.2.4.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.143 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@us.ibm.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-209 Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.