VYPR
Medium severity6.2NVD Advisory· Published Apr 7, 2026· Updated Apr 7, 2026

CVE-2025-13044

CVE-2025-13044

Description

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

Affected products

1
  • cpe:2.3:a:ibm:concert:*:*:*:*:*:*:*:*
    Range: >=1.0.0,<=2.2.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

3