Impact
The vulnerability, identified as a CWE-269 weakness (Improper Privilege Management), stems from the use of wildcard entries in role‑based access control (RBAC) permission definitions in IBM Concert Software. A malicious actor possessing valid credentials can exploit this flaw to view or alter data and settings that the attacker should not be able to modify. This results in a loss of data confidentiality, integrity, and potentially system availability if critical configurations are tampered with.
Affected Systems
IBM Concert versions 1.0.0 through 3.0.0 are affected, with the most recent vulnerable release being 3.0.0. Users running any of these versions, regardless of deployment type, are at risk until an upgrade is performed.
Risk and Exploitability
This vulnerability is a CWE-269 weakness involving improper privilege management, and the CVSS score of 9.6 indicates a high severity vulnerability that poses a significant risk to systems in use. While an EPSS score is not available, the lack of listing in the CISA KEV catalog suggests no current widespread exploitation. Nonetheless, the attack requires only an authenticated session, making it realistic for an insider or compromised account to exploit the system. Remediation is recommended promptly to prevent potential data exfiltration or configuration changes.
OpenCVE Enrichment