VYPR

Concert

by IBM

CVEs (68)

  • CVE-2025-36159MedNov 20, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

  • CVE-2025-36153MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2025-36083MedOct 28, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

  • CVE-2025-0656MedSep 1, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2025-33100MedAug 18, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-41785MedNov 15, 2024
    risk 0.40cvss 6.1epss 0.00

    IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2025-64649MedAug 28, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.

  • CVE-2025-64648MedMar 25, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2025-64647MedMar 25, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

  • CVE-2025-33101MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

  • CVE-2024-43178MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-36253MedFeb 2, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-1722MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-1719MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-1721MedDec 26, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-36150MedNov 24, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-36161MedNov 20, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

  • CVE-2025-1761MedSep 8, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-33102MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-33099MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.