Concert

Vendor:

First CVE: Sep 13, 2024 · Active for 1 year

65
Total CVEs
More Total CVEs than 99% of tracked products
21.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Concert over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 13, 2024
22 months ago
Most Recent CVE
Apr 7, 2026
112 days ago

CVE Severity & Scoring

Concert65 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local13 (20.0%)
Network52 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (81.5%)
High12 (18.5%)
Unknown0 (0.0%)
User Interaction
None55 (84.6%)
Unknown0 (0.0%)
Required10 (15.4%)
Privileges Required
Low17 (26.2%)
High0 (0.0%)
None48 (73.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.
Feb 17, 20269.835NONO
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being lim
Aug 18, 20259.831NONO
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
Oct 22, 20249.830NONO
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
Jan 20, 20268.829NONO
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Jan 20, 20267.528NONO
IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary cod
Dec 26, 20257.826NONO
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Aug 18, 20257.526NONO
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Apr 7, 20266.225NONO
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Feb 17, 20267.525NONO
IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.
Dec 26, 20257.425NONO

Exploit Exposure

Signals from CVEs in this product scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (65 CVEs).

Media Mentions

Signals from CVEs in this product scope (65 CVEs).

Top CNAs Publishing CVEs For Concert

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.0.346.00.3%00
1.0.2.167.10.3%00
1.0.277.20.3%00
1.0.1126.80.3%00
1.0.0126.80.3%00
1.014.30.2%00