CVE-2025-64649: Multiple Vulnerabilities in IBM Concert Software
Published Aug 27, 2026
·Updated
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
Other sources
IBM Concert Software could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
— IBM
Affected Software
4 affected components
IBM Concert Software<=1.0.0-2.3.1
IBM IBM Concert>=1.0.0<=2.3.1
All of the following
IBM Concert>=1.0.0<=2.3.1
Linux Linux kernel
Remediation
Information
IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.0
Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
Patch Available
Event History
Aug 27, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 28, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which IBM Concert versions are affected?
IBM Concert versions 1.0.0 through 2.3.1 are listed as affected.
2
Does exploitation require attacker credentials or user interaction?
No privileges and no user interaction are required according to the supplied vector. Exploitation is network-based but has high attack complexity.
3
What is the expected security impact?
The reported impact is high to integrity. No confidentiality or availability impact is indicated.