CVE-2025-13726

MEDIUM

IBM Sterling Partner Engagement Manager 6.2.3.0-6.2.3.5/6.2.4.0-6.2.4.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (3)
IBM/Sterling Partner Engagement Manager 6.2.3.0 - 6.2.3.5
IBM/Sterling Partner Engagement Manager 6.2.4.0 - 6.2.4.2
ibm/sterling_partner_engagement_manager 6.2.3 - 6.2.3.6 (2 CPE variants)
Published Mar 13, 2026
Tracked Since Mar 14, 2026