PT-2025-47637 · Ibm · Ibm Concert
Published
2025-11-19
·
Updated
2025-11-21
·
CVE-2025-36159
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Concert versions 1.0.0 through 2.0.0
Description
IBM Concert versions 1.0.0 through 2.0.0 are susceptible to a flaw that could allow a local user to manipulate log files. This manipulation could enable the user to impersonate other users or conceal their actions due to insufficient output sanitization. The issue involves improper neutralization of output, potentially leading to security compromises.
Recommendations
Update IBM Concert to a version later than 2.0.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Concert