Impact
IBM Concert Software versions 1.0.0 through 3.0.0 may return detailed technical error messages to a remote attacker via a web interface, allowing the attacker to gather sensitive internal information. This flaw, classified as CWE-209, can expose configuration data, stack traces, or other proprietary details that could aid subsequent attacks. The impact is the disclosure of information that is not intended for public consumption, compromising confidentiality but not directly enabling code execution or denial of service.
Affected Systems
The vulnerability affects IBM Concert Software, all releases from 1.0.0 up to and including 3.0.0. Organizations running any of these versions should review their deployments, as the flaw is tied to the web error handling component of the application.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk with typical remote access requirements. The EPSS score is not available, so current exploitation likelihood is unclear, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remotely exploitable; an attacker can trigger an internal error condition that triggers the verbose message to be displayed in a browser. Because the flaw relies on a benign web error response, no special privileges or compromise prerequisites are required beyond the ability to cause the application to produce an error visible to the attacker.
OpenCVE Enrichment