CVE-2024-51451
- EPSS -
- Veröffentlicht 04.02.2026 21:21:44
- Zuletzt bearbeitet 04.02.2026 21:21:44
IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting...
CVE-2024-43181
- EPSS -
- Veröffentlicht 04.02.2026 21:18:38
- Zuletzt bearbeitet 04.02.2026 21:18:38
IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
CVE-2025-33081
- EPSS 0.02%
- Veröffentlicht 03.02.2026 22:14:20
- Zuletzt bearbeitet 04.02.2026 16:33:44
IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.
CVE-2025-36253
- EPSS 0.01%
- Veröffentlicht 02.02.2026 23:15:59
- Zuletzt bearbeitet 03.02.2026 16:44:03
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2025-1722
- EPSS 0.05%
- Veröffentlicht 20.01.2026 15:16:16
- Zuletzt bearbeitet 26.01.2026 19:40:46
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
CVE-2025-1719
- EPSS 0.05%
- Veröffentlicht 20.01.2026 15:16:15
- Zuletzt bearbeitet 26.01.2026 19:41:26
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
CVE-2025-33015
- EPSS 0.05%
- Veröffentlicht 20.01.2026 15:04:21
- Zuletzt bearbeitet 26.01.2026 19:40:06
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
CVE-2025-64645
- EPSS 0.01%
- Veröffentlicht 26.12.2025 14:24:57
- Zuletzt bearbeitet 29.12.2025 17:38:35
IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.
CVE-2025-1721
- EPSS 0.05%
- Veröffentlicht 26.12.2025 13:15:46
- Zuletzt bearbeitet 29.12.2025 18:15:52
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
CVE-2025-12771
- EPSS 0.02%
- Veröffentlicht 26.12.2025 13:15:45
- Zuletzt bearbeitet 29.12.2025 18:23:39
IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.