CVE-2023-23482
- EPSS 0.07%
- Veröffentlicht 08.06.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:16
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack ...
CVE-2023-23481
- EPSS 0.17%
- Veröffentlicht 08.06.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:16
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...
CVE-2023-23480
- EPSS 0.17%
- Veröffentlicht 08.06.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:16
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...
CVE-2022-40615
- EPSS 0.44%
- Veröffentlicht 11.01.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:21:43
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end data...
CVE-2022-34335
- EPSS 0.47%
- Veröffentlicht 11.01.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:09:19
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
CVE-2022-34334
- EPSS 0.1%
- Veröffentlicht 10.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:09:19
IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.
CVE-2022-34348
- EPSS 0.42%
- Veröffentlicht 23.09.2022 18:15:10
- Zuletzt bearbeitet 22.05.2025 20:15:24
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X...
CVE-2022-35639
- EPSS 0.39%
- Veröffentlicht 26.07.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:11:25
IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932.