Impact
IBM Concert 1.0.0 through 2.3.1 contain an improper certificate validation flaw that allows an attacker to intercept and manipulate traffic, enabling unauthorized operations. The weakness is classified as CWE‑295 and can compromise the confidentiality and integrity of communications, potentially resulting in unauthorized remote actions.
Affected Systems
The vulnerability affects IBM's Concert Software versions 1.0.0 up to 2.3.1. Any deployment running one of these releases is at risk until upgraded to the recommended 3.0.0.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would appear to be possible remotely over the network using a man‑in‑the‑middle attack, with no prerequisite authentication. The risk level remains moderate, but mitigation is advised due to potential impact.
OpenCVE Enrichment