Lucene search

K
cveIbmCVE-2022-22358
HistoryJul 19, 2022 - 5:15 p.m.

CVE-2022-22358

2022-07-1917:15:08
CWE-611
ibm
web.nvd.nist.gov
37
8
ibm
sterling partner engagement manager
xml
xxe
vulnerability
remote attacker
nvd
security
exploit
memory resources

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

45.5%

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651.

Affected configurations

Nvd
Vulners
Node
ibmpartner_engagement_managerRange6.1.26.1.2.5essentials
OR
ibmpartner_engagement_managerRange6.1.26.1.2.5standard
OR
ibmpartner_engagement_managerRange6.2.06.2.0.3essentials
OR
ibmpartner_engagement_managerRange6.2.06.2.0.3standard
OR
ibmpartner_engagement_manager_on_cloud\/saasMatch22.2
VendorProductVersionCPE
ibmpartner_engagement_manager*cpe:2.3:a:ibm:partner_engagement_manager:*:*:*:*:essentials:*:*:*
ibmpartner_engagement_manager*cpe:2.3:a:ibm:partner_engagement_manager:*:*:*:*:standard:*:*:*
ibmpartner_engagement_manager_on_cloud\/saas22.2cpe:2.3:a:ibm:partner_engagement_manager_on_cloud\/saas:22.2:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Sterling Partner Engagement Manager",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "6.1.2"
      },
      {
        "status": "affected",
        "version": "6.2"
      }
    ]
  },
  {
    "product": "Sterling Partner Engagement Manager on Cloud",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "22.2"
      }
    ]
  }
]

Social References

More

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

45.5%

Related for CVE-2022-22358