CVE-2026-17472
- EPSS 0.3%
- Veröffentlicht 22.09.2026 21:26:50
- Zuletzt bearbeitet 24.09.2026 04:17:39
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
CVE-2026-17465
- EPSS 0.28%
- Veröffentlicht 22.09.2026 21:26:21
- Zuletzt bearbeitet 23.09.2026 18:17:07
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
CVE-2026-16426
- EPSS 0.19%
- Veröffentlicht 22.09.2026 21:22:33
- Zuletzt bearbeitet 23.09.2026 18:17:07
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2026-15915
- EPSS 0.12%
- Veröffentlicht 22.09.2026 21:21:03
- Zuletzt bearbeitet 23.09.2026 19:17:27
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
CVE-2025-12767
- EPSS 0.36%
- Veröffentlicht 22.09.2026 21:20:34
- Zuletzt bearbeitet 23.09.2026 18:17:07
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
CVE-2025-36084
- EPSS 0.16%
- Veröffentlicht 22.09.2026 21:20:10
- Zuletzt bearbeitet 23.09.2026 18:17:07
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2026-3627
- EPSS 0.51%
- Veröffentlicht 28.08.2026 20:53:37
- Zuletzt bearbeitet 02.09.2026 13:14:58
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2025-64649
- EPSS 0.22%
- Veröffentlicht 28.08.2026 20:42:47
- Zuletzt bearbeitet 02.09.2026 14:07:25
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
CVE-2025-13044
- EPSS 0.14%
- Veröffentlicht 07.04.2026 01:07:38
- Zuletzt bearbeitet 24.07.2026 23:10:00
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
CVE-2025-64648
- EPSS 0.19%
- Veröffentlicht 25.03.2026 20:38:37
- Zuletzt bearbeitet 26.03.2026 17:48:29
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.