CVE-2025-33093
07.05.2025, 11:15
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | sterling_partner_engagement_manager | 6.1.2 |
ibm | sterling_partner_engagement_manager | 6.1.2 |
ibm | sterling_partner_engagement_manager | 6.2.0 |
ibm | sterling_partner_engagement_manager | 6.2.0 |
ibm | sterling_partner_engagement_manager | 6.2.2 |
ibm | sterling_partner_engagement_manager | 6.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-260 - Password in Configuration FileThe software stores a password in a configuration file that might be accessible to actors who do not know the password.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.