PT-2022-22136 · Ibm · Ibm Sterling Partner Engagement Manager

Published

2022-10-10

·

Updated

2022-10-12

·

CVE-2022-34334

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Partner Engagement Manager version 2.0
Description The issue allows an authenticated user to impersonate another user on the system because it does not invalidate the session after logout.
Recommendations For IBM Sterling Partner Engagement Manager version 2.0, manually invalidate the session after logout to prevent impersonation until a patch is available.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2022-34334

Affected Products

Ibm Sterling Partner Engagement Manager