CVE-2022-40615 – IBM Sterling Partner Engagement Manager SQL injection
https://notcve.org/view.php?id=CVE-2022-40615
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208. • https://exchange.xforce.ibmcloud.com/vulnerabilities/236208 https://www.ibm.com/support/pages/node/6854333 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-34335 – IBM Sterling Partner Engagement Manager denial of service
https://notcve.org/view.php?id=CVE-2022-34335
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705. • https://exchange.xforce.ibmcloud.com/vulnerabilities/229705 https://www.ibm.com/support/pages/node/6854331 • CWE-400: Uncontrolled Resource Consumption •
CVE-2022-34334
https://notcve.org/view.php?id=CVE-2022-34334
IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704. IBM Sterling Partner Engagement Manager versión 2.0, no invalida la sesión después de cerrar la sesión, lo que podría permitir a un usuario autenticado hacerse pasar por otro usuario en el sistema. IBM X-Force ID: 229704 • https://exchange.xforce.ibmcloud.com/vulnerabilities/229704 https://www.ibm.com/support/pages/node/6828097 • CWE-384: Session Fixation •
CVE-2022-34348
https://notcve.org/view.php?id=CVE-2022-34348
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017. IBM Sterling Partner Engagement Manager versión 6.1, es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando procesa datos XML. Un atacante remoto podría aprovechar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. • https://exchange.xforce.ibmcloud.com/vulnerabilities/230017 https://www.ibm.com/support/pages/node/6695927 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2022-35639
https://notcve.org/view.php?id=CVE-2022-35639
IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. IBM Sterling Partner Engagement Manager versiones 6.1, 6.2 y Cloud 22.2, no limitan la duración de una conexión, lo que podría causar que el servidor no responda. IBM X-Force ID: 230932. • https://exchange.xforce.ibmcloud.com/vulnerabilities/230932 https://www.ibm.com/support/pages/node/6606969 •