CVE-2025-13882

Summary

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

Affected Software

VendorProductVersion RangeStatus
IBMSterling Partner Engagement Manager Essentials Edition6.3.0.0 <= 6.3.0.2affected
IBMSterling Partner Engagement Manager Essentials Edition6.2.4.0 <= 6.2.4.4affected
IBMSterling Partner Engagement Manager Standard Edition6.2.4.0 <= 6.2.4.4affected

Weaknesses

  • CWE-799: CWE-799 Improper Control of Interaction Frequency

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References