CVE-2026-3627: Multiple Vulnerabilities in IBM Concert Software
Published Aug 27, 2026
·Updated
IBM Concert
Affected Software
2 affected components
IBM Concert Software<=1.0.0-2.3.1
IBM IBM Concert>=1.0.0<=2.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Aug 27, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 28, 2026
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
Which IBM Concert versions are affected?
IBM Concert versions 1.0.0 through 2.3.1 are affected.
2
Does exploitation require authentication or user interaction?
No. The vulnerability is remotely exploitable with low attack complexity and requires neither privileges nor user interaction.
3
What could an attacker do after successful exploitation?
An attacker could use crafted SQL statements to view, add, modify, or delete information in the back-end database.
4
Is there evidence in the available information that systems have already been exploited?
No exploitation status or indicators of compromise are provided in the available information.