Multiple Vulnerabilities in IBM Concert Software.
Published Oct 28, 2025
6.2
MEDIUMCVSS 3.1
EPSS 0.13%
Description
IBM Concert Software
1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=2.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | Concert Software | unaffected |
|
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 2.1.0 Download IBM Concert Software 2.1.0 from Container software library section of IBM Entitled Registry ( ICR ) and follow installation instructions depending on the type of deployment.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36532 Advisory
- https://www.ibm.com/support/pages/node/7249356 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36532 | Advisory | |
| https://www.ibm.com/support/pages/node/7249356 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.