Impact
IBM Concert Software versions 1.0.0 through 3.0.0 contain an improper enforcement of storage limits that allows a remote authenticated attacker to trigger a denial of service. The flaw is classified as CWE‑400, indicating resource exhaustion. Successful exploitation would interrupt the availability of the Concert service for all users, potentially exposing the organization to downtime and loss of confidence.
Affected Systems
The affected product is IBM Concert. Vulnerable releases include IBM Concert 1.0.0 and IBM Concert 3.0.0, both of which lack the storage‑limit enforcement that is present in later releases such as 3.0.1.1. Any deployment using these versions is at risk.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the moderate severity range. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation at this time. However, the attack vector is remote and requires authenticated access, meaning an attacker with valid credentials could perform the exploit by allowing the application’s storage capacity to be exhausted. The risk is therefore moderate but potentially high if attackers can obtain credentials and cause service disruption.
OpenCVE Enrichment