PT-2022-22142 · Ibm · Ibm Sterling Partner Engagement Manager

Published

2022-11-16

·

Updated

2022-11-18

·

CVE-2022-34354

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Partner Engagement Manager version 2.0
Description The issue allows encrypted storage of client data to be stored locally, which can be read by another user on the system.
Recommendations For IBM Sterling Partner Engagement Manager version 2.0, consider restricting access to the locally stored client data to minimize the risk of unauthorized access until a fix is available.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-34354

Affected Products

Ibm Sterling Partner Engagement Manager