5.3 CVE-2025-13723

Enriched by CISA
 

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token
https://nvd.nist.gov/vuln/detail/CVE-2025-13723

Categories

CWE-324 : Use of a Key Past its Expiration Date
While the expiration of keys does not necessarily ensure that they are compromised, it is a significant concern that keys which remain in use for prolonged periods of time have a decreasing probability of integrity. For this reason, it is important to replace keys within a period of time proportional to their strength.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
IBM Sterling Partner Engagement Manager
  • 6.2.3.0 ≤ 6.2.3.5 [affected]
  • 6.2.4.0 ≤ 6.2.4.2 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry