📦 Concert

by Ibm

🔍 What is Concert?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-33088

HIGH CVSS 7.4 Feb 17, 2026

This vulnerability allows local users with knowledge of IBM Concert's system architecture to escalate privileges by exploiting incorrect file permissions on critical resources. It affects IBM Concert ...

CVE-2025-33015

HIGH CVSS 8.8 Jan 20, 2026

IBM Concert versions 1.0.0 through 2.1.0 contain an unrestricted file upload vulnerability that allows attackers to upload malicious files to the web interface. This could lead to remote code executio...

CVE-2025-64645

HIGH CVSS 7.7 Dec 26, 2025

A local privilege escalation vulnerability exists in IBM Concert due to a race condition involving symbolic link handling. This allows authenticated local users to gain elevated privileges on affected...

CVE-2025-12771

HIGH CVSS 7.8 Dec 26, 2025

CVE-2025-12771 is a stack-based buffer overflow vulnerability in IBM Concert versions 1.0.0 through 2.1.0. A local authenticated user could exploit this to execute arbitrary code with the privileges o...

CVE-2025-33090

HIGH CVSS 7.5 Aug 18, 2025

CVE-2025-33090 is a denial-of-service vulnerability in IBM Concert Software where a remote attacker can send specially crafted regular expressions that cause excessive resource consumption, potentiall...

CVE-2024-52360

HIGH CVSS 7.6 Nov 19, 2024

IBM Concert Software versions 1.0.0 through 1.0.2.1 contain a SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands. This could enable attackers to read, modify, o...

CVE-2025-33089

MEDIUM CVSS 6.5 Feb 17, 2026

IBM Concert versions 1.0.0 through 2.1.0 contain hard-coded credentials that could allow remote attackers to authenticate to the system without proper authorization. This vulnerability enables attacke...

CVE-2025-36243

MEDIUM CVSS 5.4 Feb 17, 2026

IBM Concert versions 1.0.0 through 2.1.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauthorized requests from the server. This could enable...

CVE-2025-36019

MEDIUM CVSS 6.1 Feb 17, 2026

IBM Concert for Z hub framework versions 1.0.0 through 2.1.0 contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious JavaScript into the web interf...

CVE-2024-43181

MEDIUM CVSS 6.3 Feb 4, 2026

IBM Concert versions 1.0.0 through 2.1.0 fail to properly invalidate user sessions after logout, allowing authenticated users to reuse old session tokens to impersonate other users. This affects all d...

CVE-2024-51451

MEDIUM CVSS 6.5 Feb 4, 2026

IBM Concert versions 1.0.0 through 2.1.0 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to inject malicious HTTP headers, potentially leading...

CVE-2025-36253

MEDIUM CVSS 5.9 Feb 2, 2026

IBM Concert versions 1.0.0 through 2.1.0 use weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects organizations using these versions of IBM Concert s...

CVE-2025-1722

MEDIUM CVSS 5.9 Jan 20, 2026

IBM Concert versions 1.0.0 through 2.1.0 contain a heap memory disclosure vulnerability where sensitive information from previously allocated memory could be exposed to remote attackers. This occurs d...

CVE-2025-1719

MEDIUM CVSS 5.9 Jan 20, 2026

IBM Concert versions 1.0.0 through 2.1.0 contain a heap memory disclosure vulnerability where sensitive information from previously allocated memory could be exposed to remote attackers. This occurs d...

CVE-2025-1721

MEDIUM CVSS 5.9 Dec 26, 2025

IBM Concert versions 1.0.0 through 2.1.0 contain a heap memory clearing vulnerability that could allow remote attackers to read sensitive information from previously allocated memory. This affects all...

CVE-2025-36154

MEDIUM CVSS 6.2 Dec 24, 2025

IBM Concert versions 1.0.0 through 2.1.0 store sensitive information in cleartext during recursive Docker builds, allowing local users to access credentials or other secrets. This affects organization...

CVE-2025-36150

MEDIUM CVSS 5.9 Nov 24, 2025

IBM Concert versions 1.0.0 through 2.0.0 use weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects organizations using these versions of IBM Concert f...

CVE-2025-36149

MEDIUM CVSS 6.3 Nov 21, 2025

IBM Concert Software versions 1.0.0 through 2.0.0 contain a clickjacking vulnerability (CWE-1021) that allows remote attackers to hijack user clicks. This could trick authenticated users into performi...

CVE-2025-36158

MEDIUM CVSS 5.1 Nov 20, 2025

IBM Concert versions 1.0.0 through 2.0.0 contain an uncontrolled recursive directory copying vulnerability that allows local users with specific permissions to access sensitive files they shouldn't be...

CVE-2025-36159

MEDIUM CVSS 6.2 Nov 20, 2025

IBM Concert versions 1.0.0 through 2.0.0 have a log file forgery vulnerability where local users can manipulate log entries to impersonate other users or conceal their activities. This occurs due to i...

CVE-2025-36160

MEDIUM CVSS 5.3 Nov 20, 2025

IBM Concert versions 1.0.0 through 2.0.0 disclose sensitive server information via HTTP response headers. This information leakage could help attackers gather intelligence for further attacks against ...

CVE-2025-36153

MEDIUM CVSS 6.1 Nov 20, 2025

IBM Concert versions 1.0.0 through 2.0.0 contain a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious JavaScript into the web interface. This can lead t...

CVE-2025-36161

MEDIUM CVSS 5.9 Nov 20, 2025

IBM Concert versions 1.0.0 through 2.0.0 fail to properly enable HTTP Strict-Transport-Security (HSTS), allowing man-in-the-middle attackers to intercept and potentially read sensitive information tra...

CVE-2025-36081

MEDIUM CVSS 5.3 Oct 28, 2025

IBM Concert Software versions 1.0.0 through 2.0.0 contain a log injection vulnerability (CWE-117) that allows authenticated users to modify system logs by injecting malicious input. This affects organ...

CVE-2025-36083

MEDIUM CVSS 6.2 Oct 28, 2025

IBM Concert Software versions 1.0.0 through 2.0.0 contain a heap memory clearing vulnerability that allows local users to access sensitive information from memory buffers. This affects organizations u...

CVE-2025-36085

MEDIUM CVSS 5.4 Oct 28, 2025

IBM Concert versions 1.0.0 through 2.0.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauthorized requests from the server. This could enable...

CVE-2025-33099

MEDIUM CVSS 5.9 Sep 1, 2025

IBM Concert Software versions 1.0.0 through 1.1.0 have improper certificate validation, allowing man-in-the-middle attacks. This enables attackers to intercept and potentially manipulate communication...

CVE-2025-33102

MEDIUM CVSS 5.9 Sep 1, 2025

IBM Concert Software versions 1.0.0 through 1.1.0 use weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects organizations using these vulnerable versi...

CVE-2025-33082

MEDIUM CVSS 5.4 Sep 1, 2025

IBM Concert Software versions 1.0.0 through 1.1.0 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. This could e...

CVE-2025-33083

MEDIUM CVSS 5.4 Sep 1, 2025

IBM Concert Software versions 1.0.0 through 1.1.0 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. This could e...

CVE-2025-33084

MEDIUM CVSS 5.9 Sep 1, 2025

IBM Concert Software versions 1.0.0 through 1.1.0 fail to properly enable HTTP Strict Transport Security (HSTS), allowing attackers to intercept unencrypted HTTP traffic via man-in-the-middle attacks....

CVE-2025-1759

MEDIUM CVSS 5.9 Aug 18, 2025

CVE-2025-1759 is an information disclosure vulnerability in IBM Concert Software where improper heap memory clearing allows remote attackers to read sensitive data from previously allocated memory. Th...

CVE-2025-27909

MEDIUM CVSS 5.4 Aug 18, 2025

IBM Concert Software versions 1.0.0 through 1.1.0 have an overly permissive CORS configuration that doesn't restrict allowed origins to trusted domains. This allows attackers to perform cross-origin r...

CVE-2024-49354

MEDIUM CVSS 5.3 Jan 18, 2025

IBM Concert versions 1.0.0 through 1.0.2 contain an API vulnerability that allows attackers to extract sensitive information through specially crafted API calls. This affects organizations using these...

CVE-2024-52891

MEDIUM CVSS 5.4 Jan 7, 2025

This vulnerability in IBM Concert Software allows authenticated users to inject malicious content into log files or extract sensitive information from them due to improper log neutralization. It affec...

CVE-2024-52366

MEDIUM CVSS 5.9 Jan 7, 2025

This vulnerability in IBM Concert Software allows attackers to intercept unencrypted HTTP traffic due to missing HTTP Strict Transport Security (HSTS) headers. Attackers can use man-in-the-middle tech...

CVE-2025-33081

LOW CVSS 3.3 Feb 3, 2026

IBM Concert versions 1.0.0 through 2.1.0 store sensitive information in log files that local users can read. This information disclosure vulnerability could expose credentials, configuration details, ...