Description
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
Published: 2026-09-22
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

IBM Concert Software versions 1.0.0 through 3.0.0 contain an improper enforcement of storage limits that allows a remote authenticated attacker to trigger a denial of service. The flaw is classified as CWE‑400, indicating resource exhaustion. Successful exploitation would interrupt the availability of the Concert service for all users, potentially exposing the organization to downtime and loss of confidence.

Affected Systems

The affected product is IBM Concert. Vulnerable releases include IBM Concert 1.0.0 and IBM Concert 3.0.0, both of which lack the storage‑limit enforcement that is present in later releases such as 3.0.1.1. Any deployment using these versions is at risk.

Risk and Exploitability

The CVSS score of 6.5 places this vulnerability in the moderate severity range. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation at this time. However, the attack vector is remote and requires authenticated access, meaning an attacker with valid credentials could perform the exploit by allowing the application’s storage capacity to be exhausted. The risk is therefore moderate but potentially high if attackers can obtain credentials and cause service disruption.

Generated by OpenCVE AI on September 22, 2026 at 22:25 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1 Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.


OpenCVE Recommended Actions

  • Upgrade IBM Concert Software to version 3.0.1.1 or later as a priority.
  • If an upgrade cannot be performed immediately, configure application‑level storage limits or quotas to prevent the database or storage from reaching its maximum capacity.
  • Implement monitoring or alerts for storage usage that triggers close to the configured limits, allowing administrators to intervene before a denial of service occurs.

Generated by OpenCVE AI on September 22, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
Title Multiple Vulnerabilities in IBM Concert Software
First Time appeared Ibm
Ibm concert
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm concert
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:26:21.652Z

Reserved: 2026-07-25T20:04:05.028Z

Link: CVE-2026-17465

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:07.547

Modified: 2026-09-22T22:17:07.547

Link: CVE-2026-17465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:30:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption