IBM
IBM Concert: vulnerabilidades y CVE
IBM Concert tiene 83 vulnerabilidades publicadas, 53 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE83
Últimos 12 meses53
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6544 | Media (6.2) | 0.12% | — | 24 sept 2026 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface. |
| CVE-2026-6935 | Alta (7.8) | 0.12% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can… |
| CVE-2026-6928 | Crítica (9.8) | 0.45% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application… |
| CVE-2026-6925 | Media (5.3) | 0.33% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary… |
| CVE-2026-6794 | Alta (7.8) | 0.11% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of… |
| CVE-2026-6730 | Alta (7.8) | 0.30% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. |
| CVE-2026-6721 | Crítica (9.8) | 1.4% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system.… |
| CVE-2026-6718 | Media (6.2) | 0.10% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files. |
| CVE-2026-6327 | Media (4.3) | 0.17% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. |
| CVE-2026-3626 | Media (5.3) | 0.24% | — | 23 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against… |
| CVE-2026-17472 | Crítica (9.6) | 0.30% | — | 22 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions. |
| CVE-2026-17465 | Media (6.5) | 0.28% | — | 22 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits. |
| CVE-2026-16426 | Media (6.5) | 0.19% | — | 22 sept 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or… |
| CVE-2026-15915 | Media (6.2) | 0.12% | — | 22 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images. |
| CVE-2025-36084 | Media (5.9) | 0.16% | — | 22 sept 2026 | IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. |
| CVE-2025-12767 | Media (5.3) | 0.36% | — | 22 sept 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption. |
| CVE-2026-3627 | Crítica (9.1) | 0.51% | — | 28 ago 2026 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end… |
| CVE-2025-64649 | Media (5.9) | 0.17% | — | 28 ago 2026 | IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. |
| CVE-2025-13044 | Media (6.2) | 0.14% | — | 7 abr 2026 | IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. |
| CVE-2025-64648 | Media (5.9) | 0.19% | — | 25 mar 2026 | IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. |
| CVE-2025-64647 | Alta (7.5) | 0.20% | — | 25 mar 2026 | IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information |
| CVE-2025-64646 | Media (5.5) | 0.17% | — | 25 mar 2026 | IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources. |
| CVE-2025-36440 | Media (5.5) | 0.15% | — | 25 mar 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control. |
| CVE-2025-36438 | Media (5.5) | 0.12% | — | 25 mar 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints. |
| CVE-2025-12708 | Media (5.5) | 0.09% | — | 25 mar 2026 | IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user. |
| CVE-2025-33088 | Alta (7.4) | 0.10% | — | 17 feb 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources. |
| CVE-2025-36243 | Media (4.3) | 0.14% | — | 17 feb 2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or… |
| CVE-2025-33101 | Media (5.9) | 0.21% | — | 17 feb 2026 | IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory. |
| CVE-2025-33089 | Crítica (9.8) | 0.23% | — | 17 feb 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials. |
| CVE-2025-36019 | Media (6.1) | 0.17% | — | 17 feb 2026 | IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142