CVE-2025-12767: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
Other sources
IBM Concert Software could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 3.0.1.1
Event History
Frequently Asked Questions
Which IBM Concert versions are affected?
IBM Concert versions 1.0.0 through 3.0.0 are identified as affected.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction.
What is the expected impact of a successful attack?
A remote attacker can cause denial of service by submitting a specially crafted regular expression that consumes excessive resources. The supplied severity vector indicates availability impact only, with no confidentiality or integrity impact.