CVE-2025-13882 PUBLISHED

Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.

Assigner: ibm
Reserved: 02.12.2025 Published: 18.09.2026 Updated: 18.09.2026

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor IBM
Product Sterling Partner Engagement Manager Essentials Edition
Versions
  • affected from 6.3.0.0 to 6.3.0.2 (incl.)
  • affected from 6.2.4.0 to 6.2.4.4 (incl.)
Vendor IBM
Product Sterling Partner Engagement Manager Standard Edition
Versions
  • affected from 6.2.4.0 to 6.2.4.4 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now by upgrading to the remediated version below: Product(s)Affected Version RangeRemediated VersionInstructions / DownloadIBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 – 6.3.0.26.3.0.3Download 6.3.0.3IBM Sterling Partner Engagement Manager Essentials Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5IBM Sterling Partner Engagement Manager Standard Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5

References

Problem Types

  • CWE-799 Improper Control of Interaction Frequency CWE