CVE-2025-36154

CWE-3133 documents3 sources
Severity
6.2MEDIUM
EPSS
0.0%
top 99.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24

Description

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages2 packages

NVDibm/concert1.0.02.2.0
CVEListV5ibm/concert1.0.02.1.0

🔴Vulnerability Details

2
GHSA
GHSA-r8pj-6rqm-3whh: IBM Concert 12025-12-24
CVEList
IBM Concert Software Cleartext Storage in a File or on Disk.2025-12-24
CVE-2025-36154 (MEDIUM CVSS 6.2) | IBM Concert 1.0.0 through 2.1.0 sto | cvebase.io