CVE-2025-14811

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
References
Link Resource
https://www.ibm.com/support/pages/node/7263391 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:essentials:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:essentials:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:standard:*:*:*

History

02 Apr 2026, 12:16

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7263391 - () https://www.ibm.com/support/pages/node/7263391 - Vendor Advisory
Summary
  • (es) IBM Sterling Partner Engagement Manager 6.2.3.0 a 6.2.3.5 y 6.2.4.0 a 6.2.4.2 podría permitir a un atacante obtener información sensible de la cadena de consulta de un método GET HTTP para procesar una solicitud que podría obtenerse utilizando técnicas de man-in-the-middle.
CPE cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:standard:*:*:*
cpe:2.3:a:ibm:sterling_partner_engagement_manager:*:*:*:*:essentials:*:*:*
First Time Ibm
Ibm sterling Partner Engagement Manager

13 Mar 2026, 19:53

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:53

Updated : 2026-04-02 12:16


NVD link : CVE-2025-14811

Mitre link : CVE-2025-14811

CVE.ORG link : CVE-2025-14811


JSON object : View

Products Affected

ibm

  • sterling_partner_engagement_manager
CWE
CWE-598

Use of GET Request Method With Sensitive Query Strings