Junglewise Threat Intelligence

CVE-2025-13702: IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vuln

CVE-2025-13702 · Severity: medium · CVSS 6.1 · Published 2026-03-13

Vendors: IBM.

Executive brief

IBM Sterling Partner Engagement Manager, a platform used by businesses to manage and onboard partners, is vulnerable to a security flaw that allows attackers to inject malicious scripts into its web interface. If a user interacts with a compromised part of the system, an attacker could potentially steal login credentials or perform unauthorized actions on behalf of that user. This could lead to unauthorized access to partner data or disruption of business operations.

Technical details

IBM Sterling Partner Engagement Manager is vulnerable to a cross-site scripting (XSS) flaw (CWE-79) within its Web UI. The vulnerability stems from improper neutralization of user-supplied input, which allows an attacker to embed arbitrary JavaScript code. While some reports suggest authentication is required, the vendor's CVSS vector indicates the attack can be initiated remotely without prior authentication, though it requires interaction from a victim (User Interaction: Required). Successful exploitation can lead to the disclosure of sensitive information, such as session tokens or credentials, within a trusted session. IBM has released patches in versions 6.2.3.6 and 6.2.4.3 to address this issue.

Affected products

  • IBM Sterling Partner Engagement Manager Standard Edition 6.2.3.0 - 6.2.3.5, 6.2.4.0 - 6.2.4.2
  • IBM Sterling Partner Engagement Manager Essentials Edition 6.2.3.0 - 6.2.3.5, 6.2.4.0 - 6.2.4.2

Timeline

  • 2026-03-13: advisory: Initial advisory published by IBM and NVD
  • 2026-05-10: other: CISA-ADP enrichment and CWE assignment

References