IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6568299 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/219130 | vdb entry vendor advisory |