Multiple Vulnerabilities in IBM Concert Software
Published Sep 23, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.45%
Description
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=3.0.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1
Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85669 Advisory
- https://www.ibm.com/support/pages/node/7288830 vendor-advisorypatch
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85669 | Advisory | |
| https://www.ibm.com/support/pages/node/7288830 | vendor-advisorypatch |
Change history (0)
No recorded changes yet.