CVE-2025-13718: IBM Sterling Partner Engagement Manager Information Disclosure
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
Other sources
IBM Sterling Partner Engagement Manager could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13718?
CVE-2025-13718 is classified as a high-severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2025-13718?
To resolve CVE-2025-13718, upgrade IBM Sterling Partner Engagement Manager to versions 6.2.3.6 or 6.2.4.3 or later.
What type of data is affected by CVE-2025-13718?
CVE-2025-13718 allows a remote attacker to access sensitive information transmitted in cleartext.
Which versions of IBM Sterling Partner Engagement Manager are affected by CVE-2025-13718?
CVE-2025-13718 affects versions 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2.
Is there a risk of data interception with CVE-2025-13718?
Yes, CVE-2025-13718 poses a risk of data interception as it exposes sensitive information to unauthorized actors.