Description
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

IBM Sterling Partner Engagement Manager is vulnerable to an unauthenticated denial of service in the email service caused by improper control of interaction frequency. The weakness, classified as CWE-799, allows an attacker to repeatedly trigger the email service until it becomes unavailable, potentially preventing legitimate users from sending or receiving messages. The impact is limited to availability of the email service and does not directly compromise confidentiality or integrity.

Affected Systems

Affected products include IBM Sterling Partner Engagement Manager Essentials Edition versions 6.2.4.0 through 6.2.4.4 and 6.3.0.0 through 6.3.0.2, as well as IBM Sterling Partner Engagement Manager Standard Edition versions 6.2.4.0 through 6.2.4.4. Admins should check the specific build installed and identify if it falls within these ranges.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is < 1%, suggesting a very low probability of exploitation, and the issue is not currently listed in the CISA KEV catalog, indicating that widespread exploitation is not known at present. However, because the attack vector is unauthenticated and likely accessible from the network, an attacker could mount repeated requests to the email service, leading to service disruption. The risk remains moderate but tangible if the environment relies heavily on the email functionality.

Generated by OpenCVE AI on September 19, 2026 at 18:09 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to the remediated version below: Product(s)Affected Version RangeRemediated VersionInstructions / DownloadIBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 – 6.3.0.26.3.0.3Download 6.3.0.3IBM Sterling Partner Engagement Manager Essentials Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5IBM Sterling Partner Engagement Manager Standard Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5


OpenCVE Recommended Actions

  • Upgrade IBM Sterling Partner Engagement Manager Essentials Edition to 6.3.0.3 or IBM Sterling Partner Engagement Manager Standard Edition to 6.2.4.5
  • Disable or restrict access to the email service until a patch can be applied
  • Implement rate limiting or network filtering to limit the frequency of email service requests from untrusted sources

Generated by OpenCVE AI on September 19, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
Title Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.
First Time appeared Ibm
Ibm sterling Partner Engagement Manager Essentials Edition
Ibm sterling Partner Engagement Manager Standard Edition
Weaknesses CWE-799
CPEs cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager_standard_edition:6.2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager_standard_edition:6.2.4.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling Partner Engagement Manager Essentials Edition
Ibm sterling Partner Engagement Manager Standard Edition
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ibm Sterling Partner Engagement Manager Essentials Edition Sterling Partner Engagement Manager Standard Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:21:39.873Z

Reserved: 2025-12-02T14:12:25.205Z

Link: CVE-2025-13882

cve-icon Vulnrichment

Updated: 2026-09-18T16:20:58.146Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:04.197

Modified: 2026-09-18T18:17:47.257

Link: CVE-2025-13882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:15:02Z

Weaknesses
  • CWE-799

    Improper Control of Interaction Frequency