Executive brief
IBM Sterling Partner Engagement Manager is a business-to-business communication platform used to manage partner interactions and transactions. An unauthenticated attacker can overwhelm the email service component by sending repeated requests without proper rate limiting, causing the service to become unavailable and disrupting partner communications.
Technical details
The vulnerability is an improper control of interaction frequency (CWE-799) in the email service component of IBM Sterling Partner Engagement Manager. An unauthenticated user can trigger a denial of service by repeatedly invoking email functionality without rate limiting or throttling controls in place. The attack requires no authentication, is network-accessible, and has no preconditions beyond network connectivity to the affected system. An attacker can cause the email service to become unavailable, disrupting legitimate business operations. IBM has released security updates addressing this issue.
Affected products
- IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, 6.2.4.0 through 6.2.4.4
- IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4
Timeline
- 2026-09-18: disclosed