Impact
IBM Sterling Partner Engagement Manager is vulnerable to an unauthenticated denial of service in the email service caused by improper control of interaction frequency. The weakness, classified as CWE-799, allows an attacker to repeatedly trigger the email service until it becomes unavailable, potentially preventing legitimate users from sending or receiving messages. The impact is limited to availability of the email service and does not directly compromise confidentiality or integrity.
Affected Systems
Affected products include IBM Sterling Partner Engagement Manager Essentials Edition versions 6.2.4.0 through 6.2.4.4 and 6.3.0.0 through 6.3.0.2, as well as IBM Sterling Partner Engagement Manager Standard Edition versions 6.2.4.0 through 6.2.4.4. Admins should check the specific build installed and identify if it falls within these ranges.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is < 1%, suggesting a very low probability of exploitation, and the issue is not currently listed in the CISA KEV catalog, indicating that widespread exploitation is not known at present. However, because the attack vector is unauthenticated and likely accessible from the network, an attacker could mount repeated requests to the email service, leading to service disruption. The risk remains moderate but tangible if the environment relies heavily on the email functionality.
OpenCVE Enrichment