CVE-2025-13723: IBM Sterling Partner Engagement Manager Information Disclosure
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token
Other sources
IBM Sterling Partner Engagement Manager could allow an attacker to obtain sensitive user information using an expired access token
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13723?
CVE-2025-13723 is classified as a high severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-13723?
To mitigate CVE-2025-13723, update IBM Sterling Partner Engagement Manager to the latest version above 6.2.4.2.
What type of information is disclosed in CVE-2025-13723?
CVE-2025-13723 may allow attackers to obtain sensitive user information using expired access tokens.
Which versions of IBM Sterling Partner Engagement Manager are affected by CVE-2025-13723?
IBM Sterling Partner Engagement Manager versions 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 are affected by CVE-2025-13723.
Who is the vendor responsible for addressing CVE-2025-13723?
IBM is the vendor responsible for addressing CVE-2025-13723 in their Sterling Partner Engagement Manager product.