Back

MEDIUM

Multiple Vulnerabilities in IBM Concert Software.

Published Oct 28, 2025

Description

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Affected products

Remediation

Vendor solution

Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 2.1.0 Download IBM Concert Software 2.1.0 from Container software library section of IBM Entitled Registry ( ICR ) and follow installation instructions depending on the type of deployment.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Oct 28, 2025
Updated Oct 28, 2025
Reserved Apr 15, 2025

CISA Vulnrichment

Updated Oct 28, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Oct 28, 2025
Updated Oct 28, 2025

GitHub

No data