CVE-2022-34354 MEDIUM

CVE-2022-34354: IBM Sterling Partner Engagement Manager information disclosure

Vendor Ibm
Product Partner Engagement Manager
Weakness CWE-922
Published November 16, 2022
Last update April 25, 2025

CVSS base score

4.0/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.

Key dates

02Disclosure timeline

November 16, 2022 CVE published
April 25, 2025 Record updated