Impact
The vulnerability in IBM Concert 1.0.0 through 3.0.0 arises from the use of cryptographic algorithms that are weaker than expected. This flaw can enable an attacker to decrypt highly sensitive information that the application encrypts, thereby compromising confidentiality. The weakness is identified as CWE‑327, Improper Restriction of Cryptographic Algorithms.
Affected Systems
Affected systems include IBM Concert Software released under the version numbers 1.0.0 and all releases up to 3.0.0. The vulnerability is present in these releases, and the vendor recommends applying the update to IBM Concert Software 3.0.1.1 to eliminate the problem.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk. Because EPSS is not available and the vulnerability is not in the CISA KEV catalog, the likelihood of widespread exploitation appears low, but the impact is significant if an attacker can obtain encrypted data. Attackers would most likely exploit the weakness by analyzing or brute‑forcing the weak cryptographic material, a process that requires access to the encrypted data but not necessarily privileged application or system access. Mitigations focus on applying the vendor patch to enforce strong cryptographic primitives.
OpenCVE Enrichment