Description
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
Published: 2026-09-22
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

The vulnerability originates from recursive copying of build context directories into container images within IBM Concert Software versions 1.0.0 through 3.0.0. A local attacker able to run code in the build environment can read files that were not intended to be included in the image, thereby compromising confidential data. This weakness is classified as CWE‑552, which reflects insufficient protection of internal information. The flaw does not enable remote code execution or denial of service, but it fully exposes privileged data to anyone gaining local execution rights.

Affected Systems

IBM Concert Software versions 1.0.0 to 3.0.0 are affected. The affected product includes IBM:Concert container orchestration and Docker build capabilities. The vendor recommends upgrading to IBM Concert Software 3.0.1.1 to fix the issue; all prior releases remain vulnerable.

Risk and Exploitability

The CVSS score of 6.2 indicates a medium severity. EPSS is unavailable, so the exploit probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local attacker with sufficient privileges within the build environment, making it less likely to be leveraged by remote attackers but still a significant risk for internal threats or compromised accounts.

Generated by OpenCVE AI on September 22, 2026 at 22:35 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1 Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.


OpenCVE Recommended Actions

  • Upgrade IBM Concert Software to version 3.0.1.1 to eliminate recursive copying of build context directories.
  • If upgrading is not immediately possible, remove or relocate sensitive files from the build context before they are copied into images.
  • Implement routine scanning of container images for unintended file inclusion and monitor build processes for anomalous directory copying.

Generated by OpenCVE AI on September 22, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
Title Multiple Vulnerabilities in IBM Concert Software
First Time appeared Ibm
Ibm concert
Weaknesses CWE-552
CPEs cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm concert
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:21:03.085Z

Reserved: 2026-07-15T19:41:01.816Z

Link: CVE-2026-15915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:06.470

Modified: 2026-09-22T22:17:06.470

Link: CVE-2026-15915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:45:17Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties