Medium severity6.2NVD Advisory· Published Apr 7, 2026· Updated Apr 7, 2026
CVE-2025-13044
CVE-2025-13044
Description
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7268620nvdVendor Advisory
News mentions
3- ServiceNow strengthens enterprise AI security with Autonomous Security & Risk platformHelp Net Security · May 6, 2026
- China-Backed Hackers Are Industrializing BotnetsDark Reading · Apr 23, 2026
- Moving past bots vs. humansCloudflare Blog · Apr 21, 2026