Back

MEDIUM

Multiple Vulnerabilities in IBM Concert Software.

Published Oct 28, 2025

Description

IBM Concert Software

1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

Affected products

Remediation

Vendor solution

Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 2.1.0 Download IBM Concert Software 2.1.0 from Container software library section of IBM Entitled Registry ( ICR ) and follow installation instructions depending on the type of deployment.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Oct 28, 2025
Updated Oct 28, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Oct 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Oct 28, 2025
Updated Oct 28, 2025
Exploited since n/a
EUVD-2025-36532