IBM Concert
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Concert.
By the Year
In 2026 there have been 39 vulnerabilities in IBM Concert with an average score of 6.5 out of ten. Last year, in 2025 Concert had 24 security vulnerabilities published. That is, 15 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.39.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 39 | 6.52 |
| 2025 | 24 | 6.13 |
| 2024 | 8 | 6.86 |
It may take a day or so for new Concert vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Concert Security Vulnerabilities
IBM Concert <3.0.0: Recursive Dir Copy Leak Vulnerability
CVE-2026-6544
6.2 - Medium
- September 24, 2026
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
Files or Directories Accessible to External Parties
IBM Concert 1.0.0-3.0.0 Local Command Execution via Unqualified Paths
CVE-2026-6935
7.8 - High
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
DLL preloading
IBM Concert 1.x-3.x Memory Corruption via Use-After-Free (CVE-2026-6928)
CVE-2026-6928
9.8 - Critical
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
Dangling pointer
IBM Concert 1.0.0-3.0.0 Directory Traversal via URL /..
CVE-2026-6925
5.3 - Medium
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
Directory traversal
IBM Concert 1.0.03.0.0 Double Free Heap Corruption
CVE-2026-6794
7.8 - High
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.
Double-free
IBM Concert 1.0.0-3.0.0 Buffer Overflow (CVE-2026-6730)
CVE-2026-6730
9.8 - Critical
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
Classic Buffer Overflow
IBM Concert <=3.0.0 Command Injection RCE
CVE-2026-6721
9.8 - Critical
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.
Shell injection
Improper Access Control in IBM Concert 1.0.0-3.0.0 Enables Unauthorized File Mod
CVE-2026-6718
6.2 - Medium
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.
Incorrect Default Permissions
IBM Concert 1.0.0-3.0.0 Log Injection via Improper Log Neutralization
CVE-2026-6327
4.3 - Medium
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Improper Output Neutralization for Logs
IBM Concert 1.0.0-3.0.0: Sensitive Info Exposure via Error Msg
CVE-2026-3626
5.3 - Medium
- September 23, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Generation of Error Message Containing Sensitive Information
IBM Concert 1.0.0 through 3.0.0 could
CVE-2026-17472
9.6 - Critical
- September 22, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Improper Privilege Management
IBM Concert 1.0.0 through 3.0.0 could
CVE-2026-17465
6.5 - Medium
- September 22, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
Resource Exhaustion
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF)
CVE-2026-16426
6.5 - Medium
- September 22, 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
SSRF
IBM Concert 1.0.0 through 3.0.0 could
CVE-2026-15915
6.2 - Medium
- September 22, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
Files or Directories Accessible to External Parties
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression
CVE-2025-12767
5.3 - Medium
- September 22, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
Allocation of Resources Without Limits or Throttling
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms
CVE-2025-36084
5.9 - Medium
- September 22, 2026
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Use of a Broken or Risky Cryptographic Algorithm
SQLi in IBM Concert 1.0.0-2.3.1
CVE-2026-3627
9.1 - Critical
- August 28, 2026
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
SQL Injection
IBM Concert 1.0.0-2.3.1 Improper Cert Validation MITM
CVE-2025-64649
5.9 - Medium
- August 28, 2026
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
Improper Certificate Validation
IBM Concert 1-2.2.0 Temp Files with Predictable Names Enable Local Symlink Overwrite
CVE-2025-13044
6.2 - Medium
- April 07, 2026
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Generation of Predictable Numbers or Identifiers
IBM Concert 1.0.0-2.2.0 Transmits Data in Clear Text (MITM Risk)
CVE-2025-64648
5.9 - Medium
- March 25, 2026
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Cleartext Transmission of Sensitive Information
IBM Concert 1.0.0-2.2.0 Crypto Weakness: Decrypt Sensitive Data
CVE-2025-64647
5.9 - Medium
- March 25, 2026
IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Use of a Risky Cryptographic Primitive
IBM Concert 1.0-2.2 Buffer Clear Bypass (CVE-2025-64646)
CVE-2025-64646
6.2 - Medium
- March 25, 2026
IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.
Compiler Removal of Code to Clear Buffers
IBM Concert 1.02.2: Local Data Leak via Missing FLAC
CVE-2025-36440
5.1 - Medium
- March 25, 2026
IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.
Insufficiently Protected Credentials
IBM Concert 2.2.0 Privileged User Channel Misrestriction Vulnerability
CVE-2025-36438
5.1 - Medium
- March 25, 2026
IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.
Improper Restriction of Communication Channel to Intended Endpoints
IBM Concert 1.0.0-2.2.0 Hardc Creds Local User Access
CVE-2025-12708
6.2 - Medium
- March 25, 2026
IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.
Use of Hard-coded Credentials
IBM Concert 1.0.0-2.1.0 Local Privilege Escalation via Incorrect File Permissions
CVE-2025-33088
7.4 - High
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.
Incorrect Permission Assignment for Critical Resource
IBM Concert 1.0-2.1.0 Heap Memory Info Leak via MITM
CVE-2025-33101
5.9 - Medium
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.
Heap Inspection
IBM Concert <=2.1.0 HardCoded Credentials Remote Info Disclosure
CVE-2025-33089
6.5 - Medium
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.
Use of Hard-coded Credentials
SSRF in IBM Concert 1.0.02.1.0
CVE-2025-36243
5.4 - Medium
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
SSRF
IBM Concert 1.0.0-2.1.0 weak crypto enables decryption
CVE-2024-43178
5.9 - Medium
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Use of a Broken or Risky Cryptographic Algorithm
XSRF in IBM Concert Z hub 1.0.02.1.0
CVE-2025-36018
6.5 - Medium
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Session Riding
CVE-2025-36019: IBM Concert, Z Hub Framework XSS (1.0.0-2.1.0)
CVE-2025-36019
6.1 - Medium
- February 17, 2026
IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Concert HTTP Header Injection (HOST) 1.02.1
CVE-2024-51451
6.5 - Medium
- February 04, 2026
IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Improper Neutralization of HTTP Headers for Scripting Syntax
IBM Concert 1.0.0-2.1.0: Session Invalidation Missing After Logout
CVE-2024-43181
6.3 - Medium
- February 04, 2026
IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Insufficient Session Expiration
IBM Concert 1.0-2.1 Sensitive Data Logged Locally
CVE-2025-33081
3.3 - Low
- February 03, 2026
IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.
Cleartext Storage of Sensitive Information
IBM Concert 1.0.0-2.1.0 Weak Crypto Decryption Risk
CVE-2025-36253
5.9 - Medium
- February 02, 2026
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Use of a One-Way Hash without a Salt
IBM Concert 1.0.0-2.1.0: Malicious File Upload Vulnerability
CVE-2025-33015
8.8 - High
- January 20, 2026
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
Unrestricted File Upload
IBM Concert 1.0.0-2.1.0 Heap Memory Leak via Improper Clearing
CVE-2025-1722
5.9 - Medium
- January 20, 2026
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Heap Inspection
IBM Concert 1.0.0-2.1.0 Heap Info Leak via Improper Clearing
CVE-2025-1719
5.9 - Medium
- January 20, 2026
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Heap Inspection
IBM Concert 2.1.0 Local Priv Esc via Symlink Race
CVE-2025-64645
7.7 - High
- December 26, 2025
IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.
TOCTTOU
IBM Concert 1.0.0-2.1.0 Stack-Based Buffer Overflow (buf overrun)
CVE-2025-12771
7.8 - High
- December 26, 2025
IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
Buffer Overflow
IBM Concert 1.0.0-2.1.0 Remote Heap Memory Disclosure via Improper Clearing
CVE-2025-1721
5.9 - Medium
- December 26, 2025
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Heap Inspection
IBM Concert 1.0.0-2.1.0 cleartext creds in recursive docker builds - local user
CVE-2025-36154
6.2 - Medium
- December 24, 2025
IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.
Cleartext Storage in a File or on Disk
IBM Concert 1.0.0-2.0.0 Weak Crypto Enables Decryption Attack
CVE-2025-36150
5.9 - Medium
- November 24, 2025
IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Use of a Broken or Risky Cryptographic Algorithm
IBM Concert Soft 1.0-2.0 Remote Click Hijacking Vulner
CVE-2025-36149
6.3 - Medium
- November 21, 2025
IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.
Clickjacking
IBM Concert XSS 1.0.0-2.0.0: JS code injection in Web UI
CVE-2025-36153
6.1 - Medium
- November 20, 2025
IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Concert 1.0.0-2.0.0 Local User Sensitive File Leak via Recursive Copy
CVE-2025-36158
5.1 - Medium
- November 20, 2025
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.
Stack Exhaustion
IBM Concert 1.0.0-2.0.0 Log Forgery via Improper Neutralization
CVE-2025-36159
6.2 - Medium
- November 20, 2025
IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.
Improper Output Neutralization for Logs
IBM Concert 1.0.0-2.0.0 Server Info Disclosure from HTTP Headers
CVE-2025-36160
5.3 - Medium
- November 20, 2025
IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
IBM Concert HSTS Misconfiguration Allowing Remote Info Exposure 1.0.0-2.0.0
CVE-2025-36161
5.9 - Medium
- November 20, 2025
IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Use of a Broken or Risky Cryptographic Algorithm
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Concert or by IBM? Click the Watch button to subscribe.