Concert IBM Concert

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Concert.

By the Year

In 2026 there have been 39 vulnerabilities in IBM Concert with an average score of 6.5 out of ten. Last year, in 2025 Concert had 24 security vulnerabilities published. That is, 15 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.39.

Year Vulnerabilities Average Score
2026 39 6.52
2025 24 6.13
2024 8 6.86

It may take a day or so for new Concert vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Concert Security Vulnerabilities

IBM Concert <3.0.0: Recursive Dir Copy Leak Vulnerability
CVE-2026-6544 6.2 - Medium - September 24, 2026

IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.

Files or Directories Accessible to External Parties

IBM Concert 1.0.0-3.0.0 Local Command Execution via Unqualified Paths
CVE-2026-6935 7.8 - High - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.

DLL preloading

IBM Concert 1.x-3.x Memory Corruption via Use-After-Free (CVE-2026-6928)
CVE-2026-6928 9.8 - Critical - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.

Dangling pointer

IBM Concert 1.0.0-3.0.0 Directory Traversal via URL /..
CVE-2026-6925 5.3 - Medium - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.

Directory traversal

IBM Concert 1.0.03.0.0 Double Free Heap Corruption
CVE-2026-6794 7.8 - High - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.

Double-free

IBM Concert 1.0.0-3.0.0 Buffer Overflow (CVE-2026-6730)
CVE-2026-6730 9.8 - Critical - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

Classic Buffer Overflow

IBM Concert <=3.0.0 Command Injection RCE
CVE-2026-6721 9.8 - Critical - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

Shell injection

Improper Access Control in IBM Concert 1.0.0-3.0.0 Enables Unauthorized File Mod
CVE-2026-6718 6.2 - Medium - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.

Incorrect Default Permissions

IBM Concert 1.0.0-3.0.0 Log Injection via Improper Log Neutralization
CVE-2026-6327 4.3 - Medium - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

Improper Output Neutralization for Logs

IBM Concert 1.0.0-3.0.0: Sensitive Info Exposure via Error Msg
CVE-2026-3626 5.3 - Medium - September 23, 2026

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

Generation of Error Message Containing Sensitive Information

IBM Concert 1.0.0 through 3.0.0 could
CVE-2026-17472 9.6 - Critical - September 22, 2026

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.

Improper Privilege Management

IBM Concert 1.0.0 through 3.0.0 could
CVE-2026-17465 6.5 - Medium - September 22, 2026

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.

Resource Exhaustion

IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF)
CVE-2026-16426 6.5 - Medium - September 22, 2026

IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

SSRF

IBM Concert 1.0.0 through 3.0.0 could
CVE-2026-15915 6.2 - Medium - September 22, 2026

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

Files or Directories Accessible to External Parties

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression
CVE-2025-12767 5.3 - Medium - September 22, 2026

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

Allocation of Resources Without Limits or Throttling

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms
CVE-2025-36084 5.9 - Medium - September 22, 2026

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Use of a Broken or Risky Cryptographic Algorithm

SQLi in IBM Concert 1.0.0-2.3.1
CVE-2026-3627 9.1 - Critical - August 28, 2026

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

SQL Injection

IBM Concert 1.0.0-2.3.1 Improper Cert Validation MITM
CVE-2025-64649 5.9 - Medium - August 28, 2026

IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.

Improper Certificate Validation

IBM Concert 1-2.2.0 Temp Files with Predictable Names Enable Local Symlink Overwrite
CVE-2025-13044 6.2 - Medium - April 07, 2026

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

Generation of Predictable Numbers or Identifiers

IBM Concert 1.0.0-2.2.0 Transmits Data in Clear Text (MITM Risk)
CVE-2025-64648 5.9 - Medium - March 25, 2026

IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

Cleartext Transmission of Sensitive Information

IBM Concert 1.0.0-2.2.0 Crypto Weakness: Decrypt Sensitive Data
CVE-2025-64647 5.9 - Medium - March 25, 2026

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

Use of a Risky Cryptographic Primitive

IBM Concert 1.0-2.2 Buffer Clear Bypass (CVE-2025-64646)
CVE-2025-64646 6.2 - Medium - March 25, 2026

IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

Compiler Removal of Code to Clear Buffers

IBM Concert 1.02.2: Local Data Leak via Missing FLAC
CVE-2025-36440 5.1 - Medium - March 25, 2026

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

Insufficiently Protected Credentials

IBM Concert 2.2.0 Privileged User Channel Misrestriction Vulnerability
CVE-2025-36438 5.1 - Medium - March 25, 2026

IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.

Improper Restriction of Communication Channel to Intended Endpoints

IBM Concert 1.0.0-2.2.0 Hardc Creds Local User Access
CVE-2025-12708 6.2 - Medium - March 25, 2026

IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

Use of Hard-coded Credentials

IBM Concert 1.0.0-2.1.0 Local Privilege Escalation via Incorrect File Permissions
CVE-2025-33088 7.4 - High - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.

Incorrect Permission Assignment for Critical Resource

IBM Concert 1.0-2.1.0 Heap Memory Info Leak via MITM
CVE-2025-33101 5.9 - Medium - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

Heap Inspection

IBM Concert <=2.1.0 HardCoded Credentials Remote Info Disclosure
CVE-2025-33089 6.5 - Medium - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.

Use of Hard-coded Credentials

SSRF in IBM Concert 1.0.02.1.0
CVE-2025-36243 5.4 - Medium - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

SSRF

IBM Concert 1.0.0-2.1.0 weak crypto enables decryption
CVE-2024-43178 5.9 - Medium - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Use of a Broken or Risky Cryptographic Algorithm

XSRF in IBM Concert Z hub 1.0.02.1.0
CVE-2025-36018 6.5 - Medium - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Session Riding

CVE-2025-36019: IBM Concert, Z Hub Framework XSS (1.0.0-2.1.0)
CVE-2025-36019 6.1 - Medium - February 17, 2026

IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

IBM Concert HTTP Header Injection (HOST) 1.02.1
CVE-2024-51451 6.5 - Medium - February 04, 2026

IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

Improper Neutralization of HTTP Headers for Scripting Syntax

IBM Concert 1.0.0-2.1.0: Session Invalidation Missing After Logout
CVE-2024-43181 6.3 - Medium - February 04, 2026

IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Insufficient Session Expiration

IBM Concert 1.0-2.1 Sensitive Data Logged Locally
CVE-2025-33081 3.3 - Low - February 03, 2026

IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

Cleartext Storage of Sensitive Information

IBM Concert 1.0.0-2.1.0 Weak Crypto Decryption Risk
CVE-2025-36253 5.9 - Medium - February 02, 2026

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Use of a One-Way Hash without a Salt

IBM Concert 1.0.0-2.1.0: Malicious File Upload Vulnerability
CVE-2025-33015 8.8 - High - January 20, 2026

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

Unrestricted File Upload

IBM Concert 1.0.0-2.1.0 Heap Memory Leak via Improper Clearing
CVE-2025-1722 5.9 - Medium - January 20, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Heap Inspection

IBM Concert 1.0.0-2.1.0 Heap Info Leak via Improper Clearing
CVE-2025-1719 5.9 - Medium - January 20, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Heap Inspection

IBM Concert 2.1.0 Local Priv Esc via Symlink Race
CVE-2025-64645 7.7 - High - December 26, 2025

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

TOCTTOU

IBM Concert 1.0.0-2.1.0 Stack-Based Buffer Overflow (buf overrun)
CVE-2025-12771 7.8 - High - December 26, 2025

IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

Buffer Overflow

IBM Concert 1.0.0-2.1.0 Remote Heap Memory Disclosure via Improper Clearing
CVE-2025-1721 5.9 - Medium - December 26, 2025

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Heap Inspection

IBM Concert 1.0.0-2.1.0 cleartext creds in recursive docker builds - local user
CVE-2025-36154 6.2 - Medium - December 24, 2025

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

Cleartext Storage in a File or on Disk

IBM Concert 1.0.0-2.0.0 Weak Crypto Enables Decryption Attack
CVE-2025-36150 5.9 - Medium - November 24, 2025

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Use of a Broken or Risky Cryptographic Algorithm

IBM Concert Soft 1.0-2.0 Remote Click Hijacking Vulner
CVE-2025-36149 6.3 - Medium - November 21, 2025

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

Clickjacking

IBM Concert XSS 1.0.0-2.0.0: JS code injection in Web UI
CVE-2025-36153 6.1 - Medium - November 20, 2025

IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

IBM Concert 1.0.0-2.0.0 Local User Sensitive File Leak via Recursive Copy
CVE-2025-36158 5.1 - Medium - November 20, 2025

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

Stack Exhaustion

IBM Concert 1.0.0-2.0.0 Log Forgery via Improper Neutralization
CVE-2025-36159 6.2 - Medium - November 20, 2025

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

Improper Output Neutralization for Logs

IBM Concert 1.0.0-2.0.0 Server Info Disclosure from HTTP Headers
CVE-2025-36160 5.3 - Medium - November 20, 2025

IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

IBM Concert HSTS Misconfiguration Allowing Remote Info Exposure 1.0.0-2.0.0
CVE-2025-36161 5.9 - Medium - November 20, 2025

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

Use of a Broken or Risky Cryptographic Algorithm

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Concert or by IBM? Click the Watch button to subscribe.

IBM
Vendor

IBM Concert
Product

subscribe