Lucene search

K
ibmIBM6418414641C7B5E4E27180989B435C35B6F8ED3143CA0A45F82C1A0FB5C0FF82
HistoryMar 31, 2022 - 12:04 p.m.

Security Bulletin: IBM Sterling Partner Engagement Manager is vulnerable to impersonation attack (CVE-2022-22332)

2022-03-3112:04:52
www.ibm.com
19
ibm
sterling partner engagement manager
vulnerability
impersonation attack
jwt token
cve-2022-22332
authentication mechanism
apis
fix
revocation mechanism

EPSS

0.001

Percentile

38.3%

Summary

IBM Sterling Partner Engagement Manager (CVE-2022-22332) is vulnerable to impersonation attack due to weakness in the JWT token used as an authentication mechanism in the APIs. The issue has been addressed.

Vulnerability Details

CVEID:CVE-2022-22332
**DESCRIPTION:**IBM Sterling Partner Engagement Manager could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token.
CVSS Base score: 5.6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/219131 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Sterling Partner Engagement Manager Standard Edition 6.2.0

Remediation/Fixes

Product Version Remediation/Fix
IBM Sterling Partner Engagement Manager Standard Edition 6.2.0 Fixpack 6.2.0.2

Workarounds and Mitigations

None

EPSS

0.001

Percentile

38.3%

Related for 6418414641C7B5E4E27180989B435C35B6F8ED3143CA0A45F82C1A0FB5C0FF82