Impact
IBM Sterling Partner Engagement Manager versions 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 are vulnerable to a cross‑site scripting (XSS) flaw. The flaw allows an authenticated user to embed arbitrary JavaScript code within the web user interface, which then executes in the victim’s browser. This can lead to credential disclosure or other client‑side compromise as the injected script may read and transmit session data, altering the intended functionality of the application.
Affected Systems
Affected vendors and products are IBM Sterling Partner Engagement Manager in both Essentials and Standard editions. The specific vulnerable versions include 6.2.3.0–6.2.3.5 and 6.2.4.0–6.2.4.2 for both editions.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity, while the EPSS score of less than 1 % suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication; an attacker with valid credentials can inject malicious JavaScript via the web UI, causing the victim’s browser to execute the script and potentially exfiltrate credentials.
OpenCVE Enrichment