Concert Software
Vendor:
First CVE: Mar 6, 2025 · Active for 1 year
19
Total CVEs
More Total CVEs than 95% of tracked products
19.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Concert Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2025
16 months ago
Most Recent CVE
Oct 28, 2025
272 days ago
CVE Severity & Scoring
Concert Software19 CVEs
58%
37%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (84.2%)
High3 (15.8%)
Unknown0 (0.0%)
User Interaction
None16 (84.2%)
Unknown0 (0.0%)
Required3 (15.8%)
Privileges Required
Low4 (21.1%)
High0 (0.0%)
None15 (78.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27909CRITICAL IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being lim | Aug 18, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-1759HIGH IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Aug 18, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-1761HIGH IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Sep 8, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-33100HIGH IBM Concert Software 1.0.0 through 1.1.0
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound comm | Aug 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-33090HIGH IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource | Aug 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-49827HIGH IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering. | Aug 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-33102HIGH IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Sep 1, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-51476HIGH IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | Mar 6, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-33084MEDIUM IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An | Sep 1, 2025 | 5.9 | 21 | NO | NO |
CVE-2025-0656MEDIUM IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI t | Sep 1, 2025 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Concert Software
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.5 | 1 | 7.5 | 0.4% | 0 | 0 |