CVE-2025-36084: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Concert Software uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 3.0.1.1
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Concert Software versions 1.0.0 through 3.0.0 are identified as affected.
What access does an attacker need?
The vector is network-based and no privileges or user interaction are required. Exploitation is rated as high complexity.
What is the potential impact?
An attacker could decrypt highly sensitive information. The reported impact is limited to confidentiality; no integrity or availability impact is indicated.