CVE-2022-22331
CVE-2022-22331
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
01 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.
CVSS:3.0/I:L/C:L/AV:N/S:U/UI:N/AC:L/PR:L/A:N/RC:C/RL:O/E:U
Affected products
IBM · SterlingPartner Engagement Manager