IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7263391 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Apr 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ibm.com/support/pages/node/7263391 - Vendor Advisory | |
| Summary |
|
|
| CPE | cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:standard:*:*:* cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:essentials:*:*:* |
|
| First Time |
Ibm
Ibm sterling Partner Engagement Manager |
13 Mar 2026, 19:53
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-13 19:53
Updated : 2026-04-02 12:16
NVD link : CVE-2025-14811
Mitre link : CVE-2025-14811
CVE.ORG link : CVE-2025-14811
JSON object : View
Products Affected
ibm
- sterling_partner_engagement_manager
CWE
CWE-598
Use of GET Request Method With Sensitive Query Strings
