Multiple Vulnerabilities in IBM Concert Software.
Published Oct 28, 2025
5.4
MEDIUMCVSS 3.1
EPSS 0.18%
Description
IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected products
-
Affected
- ≥ 1.0.0, ≤ 2.0.0
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 2.1.0 Download IBM Concert Software 2.1.0 from Container software library section of IBM Entitled Registry ( ICR ) and follow installation instructions depending on the type of deployment.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36533 Advisory
- https://www.ibm.com/support/pages/node/7249356 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36533 | Advisory | |
| https://www.ibm.com/support/pages/node/7249356 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data