Back

MEDIUM

Multiple Vulnerabilities in IBM Concert Software

Published Sep 24, 2026

Description

IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1

Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Sep 24, 2026
Updated Sep 24, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Awaiting Analysis
Modified Sep 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Sep 24, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-86009