CVE-2025-64649: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
Other sources
IBM Concert Software could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
Which IBM Concert versions are affected?
IBM Concert versions 1.0.0 through 2.3.1 are listed as affected.
Does exploitation require attacker credentials or user interaction?
No privileges and no user interaction are required according to the supplied vector. Exploitation is network-based but has high attack complexity.
What is the expected security impact?
The reported impact is high to integrity. No confidentiality or availability impact is indicated.