PT-2022-22936 · Ibm · Ibm Sterling Partner Engagement Manager

Published

2022-07-26

·

Updated

2022-08-02

·

CVE-2022-35639

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Sterling Partner Engagement Manager versions 6.1 through 6.2 IBM Sterling Partner Engagement Manager Cloud version 22.2
Description The issue is related to the lack of connection length limitation, which could cause the server to become unresponsive.
Recommendations For IBM Sterling Partner Engagement Manager versions 6.1 through 6.2, consider implementing connection length limits to prevent the server from becoming unresponsive. For IBM Sterling Partner Engagement Manager Cloud version 22.2, consider implementing connection length limits to prevent the server from becoming unresponsive. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-35639

Affected Products

Ibm Sterling Partner Engagement Manager