Concert
Vendor:
First CVE: Sep 13, 2024 · Active for 1 year
65
Total CVEs
More Total CVEs than 99% of tracked products
21.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Concert over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 13, 2024
22 months ago
Most Recent CVE
Apr 7, 2026
112 days ago
CVE Severity & Scoring
Concert65 CVEs
60%
32%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (20.0%)
Network52 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (81.5%)
High12 (18.5%)
Unknown0 (0.0%)
User Interaction
None55 (84.6%)
Unknown0 (0.0%)
Required10 (15.4%)
Privileges Required
Low17 (26.2%)
High0 (0.0%)
None48 (73.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-33089CRITICAL IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials. | Feb 17, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-27909CRITICAL IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being lim | Aug 18, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-43177CRITICAL IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. | Oct 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-33015HIGH IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. | Jan 20, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-1719HIGH IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Jan 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-12771HIGH IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary cod | Dec 26, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-1759HIGH IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Aug 18, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-13044MEDIUM IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. | Apr 7, 2026 | 6.2 | 25 | NO | NO |
CVE-2024-43178HIGH IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Feb 17, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-64645HIGH IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link. | Dec 26, 2025 | 7.4 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (65 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (65 CVEs).
Media Mentions
Signals from CVEs in this product scope (65 CVEs).
Top CNAs Publishing CVEs For Concert
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.3 | 4 | 6.0 | 0.3% | 0 | 0 |
| 1.0.2.1 | 6 | 7.1 | 0.3% | 0 | 0 |
| 1.0.2 | 7 | 7.2 | 0.3% | 0 | 0 |
| 1.0.1 | 12 | 6.8 | 0.3% | 0 | 0 |
| 1.0.0 | 12 | 6.8 | 0.3% | 0 | 0 |
| 1.0 | 1 | 4.3 | 0.2% | 0 | 0 |