Impact
The vulnerability is a server‑side request forgery that allows an authenticated user to instruct the IBM Concert server to make arbitrary outbound HTTP requests, potentially exposing internal network resources or facilitating further attacks. The flaw requires valid credentials but does not necessarily grant privileged system access; however, the ability to reach arbitrary endpoints can be leveraged to enumerate a network, exfiltrate data, or pivot to other services.
Affected Systems
IBM Concert Software versions 1.0.0 through 3.0.0 are affected. The recommendation from IBM is to upgrade to version 3.0.1.1 to resolve the issue.
Risk and Exploitability
The CVSS score for this vulnerability is 6.5, indicating moderate severity. EPSS is not available, so exact exploitation prevalence is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires authentication to the Concert system, but once authenticated, the attacker can carry out request forgery that may lead to network enumeration or other malicious activities.
OpenCVE Enrichment