Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.25%—IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI18/9/202618/9/2026
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of…
AnalizadaMedia (5.9)0.21%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
AnalizadaAlta (7.5)0.33%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.
AnalizadaAlta (7.5)0.17%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token
AnalizadaAlta (7.5)0.18%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
ModificadaMedia (5.4)0.21%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
AnalizadaAlta (7.5)0.37%—IBM Sterling Partner Engagement Manager7/5/202517/6/2026
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.
ModificadaMedia (5.5)0.18%—IBM Sterling Partner Engagement Manager16/7/202417/6/2026
IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is returned. IBM X-Force ID: 230933.
AnalizadaMedia (5.4)0.30%—IBM Sterling Partner Engagement Manager13/3/202417/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250421.
ModificadaAlta (7.5)0.73%—IBM Sterling Partner Engagement Manager23/10/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.
ModificadaMedia (5.4)0.32%—IBM Sterling Partner Engagement Manager23/10/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:…
ModificadaCrítica (9.6)0.61%—IBM Sterling Partner Engagement Manager8/6/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks…
ModificadaMedia (5.4)0.37%—IBM Sterling Partner Engagement Manager8/6/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:…
ModificadaMedia (5.4)0.37%—IBM Sterling Partner Engagement Manager8/6/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245885.
ModificadaCrítica (9.8)0.69%—IBM Sterling Partner Engagement Manager11/1/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.
ModificadaMedia (6.5)0.71%—IBM Sterling Partner Engagement Manager11/1/202317/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
ModificadaBaja (3.3)0.20%—IBM Partner Engagement Manager16/11/202217/6/2026
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.
ModificadaMedia (6.5)0.37%—IBM Sterling Partner Engagement Manager10/10/202217/6/2026
IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.
ModificadaAlta (7.1)1.7%—IBM Sterling Partner Engagement Manager23/9/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.
ModificadaAlta (7.5)0.98%—IBM Sterling Partner Engagement ManagerIBM Sterling Partner Engagement Manager ON Cloud26/7/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932.
ModificadaMedia (5.4)0.50%—IBM Partner Engagement ManagerIBM Partner Engagement Manager ON Cloud/saas19/7/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…
ModificadaMedia (5.4)0.45%—IBM Partner Engagement ManagerIBM Partner Engagement Manager ON Cloud/saas19/7/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126.
ModificadaAlta (8.8)1.7%—IBM Partner Engagement ManagerIBM Partner Engagement Manager ON Cloud/saas19/7/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID:…
ModificadaMedia (6.5)0.30%—IBM Partner Engagement ManagerIBM Partner Engagement Manager ON Cloud/saas19/7/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.
ModificadaAlta (7.1)1.3%—IBM Partner Engagement ManagerIBM Partner Engagement Manager ON Cloud/saas19/7/202217/6/2026
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651.