CVE-2025-13882
Last modified
CVE-2025-13882 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency..
Description
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| IBM | Sterling Partner Engagement Manager Essentials Edition | >= 6.3.0.0, <= 6.3.0.2; >= 6.2.4.0, <= 6.2.4.4 |
| IBM | Sterling Partner Engagement Manager Standard Edition | >= 6.2.4.0, <= 6.2.4.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-13882?
How severe is CVE-2025-13882?
How do I fix CVE-2025-13882?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13877A vulnerability was detected in nocobase up to 1.9.4/2.0.0-a…5.6
- CVE-2025-13878Malformed BRID/HHIT records can cause `named` to terminate u…7.5
- CVE-2025-13879Directory traversal vulnerability in SOLIDserver IPAM v8.2.3…2.7
- CVE-2025-1388Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload …8.8
- CVE-2025-13880The WP Social Ninja – Embed Social Feeds, Customer Reviews, …6.5
- CVE-2025-13881A flaw was found in Keycloak Admin API. This vulnerability a…2.7
- CVE-2025-13884The Hide Email Address plugin for WordPress is vulnerable to…6.4
- CVE-2025-13885The Zenost Shortcodes plugin for WordPress is vulnerable to …6.4
- CVE-2025-13886The LT Unleashed plugin for WordPress is vulnerable to Local…7.5
- CVE-2025-13887The AI BotKit – AI Chatbot & Live Support for WordPress plug…6.4
- CVE-2025-13888A flaw was found in OpenShift GitOps. Namespace admins can c…9.1
- CVE-2025-13889The Simple Nivo Slider plugin for WordPress is vulnerable to…6.4
Are you affected by CVE-2025-13882?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
