Multiple Vulnerabilities in IBM Concert Software
Published Sep 23, 2026
7.8
HIGHCVSS 3.1
EPSS 0.12%
Description
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
Affected products
-
Affected
- ≥ 1.0.0, ≤ 3.0.0
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1
Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85670 Advisory
- https://www.ibm.com/support/pages/node/7288830 vendor-advisorypatch
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85670 | Advisory | |
| https://www.ibm.com/support/pages/node/7288830 | vendor-advisorypatch |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data