{"api_version":"1","generated_at":"2026-10-02T21:59:50+00:00","cve":"CVE-2025-13882","urls":{"html":"https://cve.report/CVE-2025-13882","api":"https://cve.report/api/cve/CVE-2025-13882.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-13882","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-13882"},"summary":{"title":"Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.","description":"IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4  could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-18 15:17:04","updated_at":"2026-09-18 18:17:47"},"problem_types":["CWE-799","CWE-799 CWE-799 Improper Control of Interaction Frequency"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7288365","name":"https://www.ibm.com/support/pages/node/7288365","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-13882","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13882","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Sterling Partner Engagement Manager Essentials Edition","version":"affected 6.3.0.0 6.3.0.2 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Sterling Partner Engagement Manager Essentials Edition","version":"affected 6.2.4.0 6.2.4.4 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Sterling Partner Engagement Manager Standard Edition","version":"affected 6.2.4.0 6.2.4.4 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now by upgrading to the remediated version below:\nProduct(s)Affected Version RangeRemediated VersionInstructions / DownloadIBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 – 6.3.0.26.3.0.3Download 6.3.0.3IBM Sterling Partner Engagement Manager Essentials Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5IBM Sterling Partner Engagement Manager Standard Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"13882","cve":"CVE-2025-13882","epss":"0.004200000","percentile":"0.358650000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-13882","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-18T16:20:46.706570Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-18T16:21:39.873Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.3.0.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:sterling_partner_engagement_manager_essentials_edition:6.2.4.4:*:*:*:*:*:*:*"],"product":"Sterling Partner Engagement Manager Essentials Edition","vendor":"IBM","versions":[{"lessThanOrEqual":"6.3.0.2","status":"affected","version":"6.3.0.0","versionType":"semver"},{"lessThanOrEqual":"6.2.4.4","status":"affected","version":"6.2.4.0","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:sterling_partner_engagement_manager_standard_edition:6.2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:sterling_partner_engagement_manager_standard_edition:6.2.4.4:*:*:*:*:*:*:*"],"product":"Sterling Partner Engagement Manager Standard Edition","vendor":"IBM","versions":[{"lessThanOrEqual":"6.2.4.4","status":"affected","version":"6.2.4.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4  could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.</p>"}],"value":"IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4  could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-799","description":"CWE-799 Improper Control of Interaction Frequency","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T14:33:52.057Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7288365"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly recommends addressing the vulnerability now by upgrading to the remediated version below:</p><div><table><colgroup><col/><col/><col/><col/></colgroup><tbody><tr><th>Product(s)</th><th>Affected Version Range</th><th>Remediated Version</th><th>Instructions / Download</th></tr><tr><td>IBM Sterling Partner Engagement Manager Essentials Edition </td><td>6.3.0.0 – 6.3.0.2</td><td>6.3.0.3</td><td><a href=\"https://www.ibm.com/support/fixcentral/swg/selectFixes?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&amp;fixids=IBM_PEM_Essentials_6.3.0.3&amp;source=SAR&amp;function=fixId&amp;parent=ibm/Other%20software\" rel=\"nofollow\">Download 6.3.0.3</a></td></tr><tr><td>IBM Sterling Partner Engagement Manager Essentials Edition</td><td>6.2.4.0 – 6.2.4.4</td><td>6.2.4.5</td><td><a href=\"https://www.ibm.com/support/fixcentral/swg/selectFixes?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&amp;fixids=IBM_PEM_Essentials_6.2.4.5&amp;source=SAR&amp;function=fixId&amp;parent=ibm/Other%20software\" rel=\"nofollow\">Download 6.2.4.5</a></td></tr><tr><td>IBM Sterling Partner Engagement Manager Standard Edition</td><td>6.2.4.0 – 6.2.4.4</td><td>6.2.4.5</td><td><a href=\"https://www.ibm.com/support/fixcentral/swg/selectFix?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&amp;fixids=IBM_PEM_Standard_6.2.4.5&amp;source=SAR&amp;function=fixId&amp;parent=ibm/Other%20software\" rel=\"nofollow\">Download 6.2.4.5</a></td></tr></tbody></table></div>"}],"value":"IBM strongly recommends addressing the vulnerability now by upgrading to the remediated version below:\nProduct(s)Affected Version RangeRemediated VersionInstructions / DownloadIBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 – 6.3.0.26.3.0.3Download 6.3.0.3IBM Sterling Partner Engagement Manager Essentials Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5IBM Sterling Partner Engagement Manager Standard Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5"}],"title":"Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager."}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2025-13882","datePublished":"2026-09-18T14:33:52.057Z","dateReserved":"2025-12-02T14:12:25.205Z","dateUpdated":"2026-09-18T16:21:39.873Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 15:17:04","lastModifiedDate":"2026-09-18 18:17:47","problem_types":["CWE-799","CWE-799 CWE-799 Improper Control of Interaction Frequency"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-18T16:20:46.706570Z","id":"CVE-2025-13882","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"13882","Ordinal":"1","Title":"Multiple Security Vulnerabilities in IBM Sterling Partner Engage","CVE":"CVE-2025-13882","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"13882","Ordinal":"1","NoteData":"IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4  could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency.","Type":"Description","Title":"Multiple Security Vulnerabilities in IBM Sterling Partner Engage"}]}}}