CVE-2025-13726: IBM Sterling Partner Engagement Manager Information Disclosure
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.
Other sources
IBM Sterling Partner Engagement Manager could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13726?
The severity of CVE-2025-13726 is considered to be medium due to the potential for sensitive information disclosure.
How do I fix CVE-2025-13726?
To fix CVE-2025-13726, you should upgrade IBM Sterling Partner Engagement Manager to the latest patched version beyond 6.2.4.2.
Which versions of IBM Sterling Partner Engagement Manager are affected by CVE-2025-13726?
CVE-2025-13726 affects IBM Sterling Partner Engagement Manager versions 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2.
What kind of information could be disclosed due to CVE-2025-13726?
CVE-2025-13726 could disclose sensitive information through detailed technical error messages returned to a remote attacker.
Is there a workaround for CVE-2025-13726?
There are currently no documented workarounds for CVE-2025-13726, and upgrading is recommended to mitigate the risk.