« Volver al listado

IBM

IBM Concert: vulnerabilidades y CVE

IBM Concert tiene 83 vulnerabilidades publicadas, 53 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE83
Últimos 12 meses53
Críticas8
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-6544Media (6.2)0.12%—24 sept 2026
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
CVE-2026-6935Alta (7.8)0.12%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can…
CVE-2026-6928Crítica (9.8)0.45%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application…
CVE-2026-6925Media (5.3)0.33%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary…
CVE-2026-6794Alta (7.8)0.11%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of…
CVE-2026-6730Alta (7.8)0.30%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
CVE-2026-6721Crítica (9.8)1.4%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system.…
CVE-2026-6718Media (6.2)0.10%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.
CVE-2026-6327Media (4.3)0.17%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
CVE-2026-3626Media (5.3)0.24%—23 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against…
CVE-2026-17472Crítica (9.6)0.30%—22 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
CVE-2026-17465Media (6.5)0.28%—22 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
CVE-2026-16426Media (6.5)0.19%—22 sept 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or…
CVE-2026-15915Media (6.2)0.12%—22 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
CVE-2025-36084Media (5.9)0.16%—22 sept 2026
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2025-12767Media (5.3)0.36%—22 sept 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
CVE-2026-3627Crítica (9.1)0.51%—28 ago 2026
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end…
CVE-2025-64649Media (5.9)0.17%—28 ago 2026
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
CVE-2025-13044Media (6.2)0.14%—7 abr 2026
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
CVE-2025-64648Media (5.9)0.19%—25 mar 2026
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
CVE-2025-64647Alta (7.5)0.20%—25 mar 2026
IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
CVE-2025-64646Media (5.5)0.17%—25 mar 2026
IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.
CVE-2025-36440Media (5.5)0.15%—25 mar 2026
IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.
CVE-2025-36438Media (5.5)0.12%—25 mar 2026
IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.
CVE-2025-12708Media (5.5)0.09%—25 mar 2026
IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.
CVE-2025-33088Alta (7.4)0.10%—17 feb 2026
IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.
CVE-2025-36243Media (4.3)0.14%—17 feb 2026
IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or…
CVE-2025-33101Media (5.9)0.21%—17 feb 2026
IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.
CVE-2025-33089Crítica (9.8)0.23%—17 feb 2026
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.
CVE-2025-36019Media (6.1)0.17%—17 feb 2026
IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application8
  2. T1068 Exploitation for Privilege Escalation6
  3. T1005 Data from Local System5
  4. T1059 Command and Scripting Interpreter4
  5. T1210 Exploitation of Remote Services3
  6. T1499.004 Application or System Exploitation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de IBM