cbcvebase.

Ibm Concert vulnerabilities

65 known vulnerabilities affecting ibm/concert.

Total CVEs
65
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21MEDIUM39LOW1

Vulnerabilities

Page 1 of 4
CVE-2024-52360P3CRITICALCVSS 9.8v1.0.0v1.0.1+2 more2024-11-19
CVE-2024-52360 [CRITICAL] CWE-89 CVE-2024-52360: IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attac IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2025-33089P3CRITICALCVSS 9.8≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-02-17
CVE-2025-33089 [CRITICAL] CWE-798 CVE-2025-33089: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or per IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.
nvd
CVE-2024-52359P3HIGHCVSS 8.8v1.0.0v1.0.1+2 more2024-11-19
CVE-2024-52359 [HIGH] CWE-286 CVE-2024-52359: IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform u IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls.
nvd
CVE-2025-27909P3CRITICALCVSS 9.8≥ 1.0.0, < 2.0.02025-08-18
CVE-2025-27909 [CRITICAL] CWE-942 CVE-2025-27909: IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
nvd
CVE-2025-33015P3HIGHCVSS 8.8≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-01-20
CVE-2025-33015 [HIGH] CWE-434 CVE-2025-33015: IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
nvd
CVE-2025-33100P3HIGHCVSS 7.5≥ 1.0.0, < 2.0.02025-08-18
CVE-2025-33100 [HIGH] CWE-798 CVE-2025-33100: IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cr IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
nvd
CVE-2024-43177P3CRITICALCVSS 9.8v1.0.0v1.0.1+1 more2024-10-22
CVE-2024-43177 [CRITICAL] CWE-295 CVE-2024-43177: IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSi IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
nvd
CVE-2025-12771P3HIGHCVSS 7.8≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02025-12-26
CVE-2025-12771 [HIGH] CWE-119 CVE-2025-12771: IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper b IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
nvd
CVE-2025-1719P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-01-20
CVE-2025-1719 [HIGH] CWE-244 CVE-2025-1719: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from a IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2025-1722P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-01-20
CVE-2025-1722 [HIGH] CWE-244 CVE-2025-1722: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from a IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2024-49354P3HIGHCVSS 7.5v1.0.0v1.0.1+1 more2025-01-18
CVE-2024-49354 [HIGH] CWE-213 CVE-2024-49354: IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specia IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.
nvd
CVE-2025-1721P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02025-12-26
CVE-2025-1721 [HIGH] CWE-244 CVE-2025-1721: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from a IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2025-36160P3HIGHCVSS 7.5≥ 1.0.0, < 2.1.0≥ 1.0.0, ≤ 2.0.02025-11-20
CVE-2025-36160 [HIGH] CWE-497 CVE-2025-36160: IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response heade IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.
nvd
CVE-2024-49827P3HIGHCVSS 7.5≥ 1.0.0, < 2.0.02025-08-18
CVE-2024-49827 [HIGH] CWE-213 CVE-2024-49827: IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attacker IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.
nvd
CVE-2025-36253P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-02-02
CVE-2025-36253 [HIGH] CWE-759 CVE-2025-36253: IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2025-64647P3HIGHCVSS 7.5≥ 1.0.0, ≤ 2.2.02026-03-25
CVE-2025-64647 [HIGH] CWE-1240 CVE-2025-64647: IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
nvd
CVE-2025-36150P3HIGHCVSS 7.5≥ 1.0.0, ≤ 2.0.02025-11-24
CVE-2025-36150 [HIGH] CWE-327 CVE-2025-36150: IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2024-43178P3HIGHCVSS 7.5≥ 1.0.0, < 2.2.0≥ 1.0.0, ≤ 2.1.02026-02-17
CVE-2024-43178 [HIGH] CWE-327 CVE-2024-43178: IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2025-1761P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.1.02025-09-08
CVE-2025-1761 [HIGH] CWE-824 CVE-2025-1761: IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive informati IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
CVE-2025-1759P3HIGHCVSS 7.5≥ 1.0.0, < 2.0.02025-08-18
CVE-2025-1759 [HIGH] CWE-244 CVE-2025-1759: IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive informati IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
nvd
Ibm Concert vulnerabilities | cvebase