Impact
IBM Concert Software versions 1.0.0 through 3.0.0 contain a flaw where an attacker can supply a specially crafted regular expression. Executing that expression causes the system to consume excessive CPU and memory resources, ultimately resulting in a denial of service. This is a resource exhaustion vulnerability classified as CWE-770.
Affected Systems
Affected users are operating IBM Concert Software 1.0.0 or 3.0.0, as indicated by the CPE strings. All installations of these releases should confirm their version to assess exposure.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available and the vulnerability is not in the CISA KEV catalog, implying no known widespread exploits. The likely attack vector is a remote attacker sending a crafted regular expression over a network interface, leading to resource exhaustion and service disruption.
OpenCVE Enrichment