Severity
5.5MEDIUM
EPSS
0.0%
top 94.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 20
Latest updateNov 21

Description

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 1.4 | Impact: 3.6

Affected Packages2 packages

NVDibm/concert1.0.02.1.0
CVEListV5ibm/concert1.0.02.0.0

🔴Vulnerability Details

2
GHSA
GHSA-xv9f-3jvg-gc4h: IBM Concert 12025-11-21
CVEList
IBM Concert Information Disclosure2025-11-20

📋Vendor Advisories

1
Microsoft
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value aka CID-52021-01-12
CVE-2025-36158 (MEDIUM CVSS 5.5) | IBM Concert 1.0.0 through 2.0.0 cou | cvebase.io