Ibm Concert vulnerabilities
65 known vulnerabilities affecting ibm/concert.
Total CVEs
65
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21MEDIUM39LOW1
Vulnerabilities
Page 1 of 4
CVE-2024-52360P3CRITICALCVSS 9.8v1.0.0v1.0.1+2 more2024-11-19
CVE-2024-52360 [CRITICAL] CWE-89 CVE-2024-52360: IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attac
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2025-33089P3CRITICALCVSS 9.8≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-02-17
CVE-2025-33089 [CRITICAL] CWE-798 CVE-2025-33089: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or per
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.
nvd
CVE-2024-52359P3HIGHCVSS 8.8v1.0.0v1.0.1+2 more2024-11-19
CVE-2024-52359 [HIGH] CWE-286 CVE-2024-52359: IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform u
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls.
nvd
CVE-2025-27909P3CRITICALCVSS 9.8≥ 1.0.0, < 2.0.02025-08-18
CVE-2025-27909 [CRITICAL] CWE-942 CVE-2025-27909: IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
nvd
CVE-2025-33015P3HIGHCVSS 8.8≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-01-20
CVE-2025-33015 [HIGH] CWE-434 CVE-2025-33015: IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
nvd
CVE-2025-33100P3HIGHCVSS 7.5≥ 1.0.0, < 2.0.02025-08-18
CVE-2025-33100 [HIGH] CWE-798 CVE-2025-33100: IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cr
IBM Concert Software 1.0.0 through 1.1.0
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
nvd
CVE-2024-43177P3CRITICALCVSS 9.8v1.0.0v1.0.1+1 more2024-10-22
CVE-2024-43177 [CRITICAL] CWE-295 CVE-2024-43177: IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSi
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
nvd
CVE-2025-12771P3HIGHCVSS 7.8≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02025-12-26
CVE-2025-12771 [HIGH] CWE-119 CVE-2025-12771: IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper b
IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
nvd
CVE-2025-1719P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-01-20
CVE-2025-1719 [HIGH] CWE-244 CVE-2025-1719: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from a
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2025-1722P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-01-20
CVE-2025-1722 [HIGH] CWE-244 CVE-2025-1722: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from a
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2024-49354P3HIGHCVSS 7.5v1.0.0v1.0.1+1 more2025-01-18
CVE-2024-49354 [HIGH] CWE-213 CVE-2024-49354: IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specia
IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.
nvd
CVE-2025-1721P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02025-12-26
CVE-2025-1721 [HIGH] CWE-244 CVE-2025-1721: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from a
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2025-36160P3HIGHCVSS 7.5≥ 1.0.0, < 2.1.0≥ 1.0.0, ≤ 2.0.02025-11-20
CVE-2025-36160 [HIGH] CWE-497 CVE-2025-36160: IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response heade
IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.
nvd
CVE-2024-49827P3HIGHCVSS 7.5≥ 1.0.0, < 2.0.02025-08-18
CVE-2024-49827 [HIGH] CWE-213 CVE-2024-49827: IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attacker
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.
nvd
CVE-2025-36253P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-02-02
CVE-2025-36253 [HIGH] CWE-759 CVE-2025-36253: IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2025-64647P3HIGHCVSS 7.5≥ 1.0.0, ≤ 2.2.02026-03-25
CVE-2025-64647 [HIGH] CWE-1240 CVE-2025-64647: IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow
IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
nvd
CVE-2025-36150P3HIGHCVSS 7.5≥ 1.0.0, ≤ 2.0.02025-11-24
CVE-2025-36150 [HIGH] CWE-327 CVE-2025-36150: IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow
IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2024-43178P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-02-17
CVE-2024-43178 [HIGH] CWE-327 CVE-2024-43178: IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2025-1761P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.1.02025-09-08
CVE-2025-1761 [HIGH] CWE-824 CVE-2025-1761: IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive informati
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2025-1759P3HIGHCVSS 7.5≥ 1.0.0, < 2.0.02025-08-18
CVE-2025-1759 [HIGH] CWE-244 CVE-2025-1759: IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive informati
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
1 / 4Next →