Description
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Published: 2026-08-28
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw found in IBM Concert 1.0.0 through 2.3.1. A remote attacker can craft SQL statements that the application blindly executes against its back‑end database. This allows the attacker to read, insert, update, or delete database records, compromising the confidentiality, integrity, and availability of the stored information.

Affected Systems

Affected products are IBM Concert Software, versions 1.0.0 to 2.3.1. The update to version 3.0.0 has been released to address the issue. No specific patches for earlier releases are listed, so upgrading to the new major release is required.

Risk and Exploitability

The CVSS score of 9.1 signals a critical vulnerability. The EPSS is not available, and the vulnerability is not on the CISA KEV list, but the high CVSS encourages urgency. The lack of an official workaround means the vulnerability must be resolved by upgrading. Remote exploitation is inferred as the attack vector, based on the ability to send crafted SQL statements over the network to the application’s interface.

Generated by OpenCVE AI on August 28, 2026 at 23:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.0 Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.


OpenCVE Recommended Actions

  • Upgrade IBM Concert Software to version 3.0.0 using the IBM Container Library or installation instructions.
  • Verify that the application no longer exposes vulnerable entry points and that database credentials are secured.
  • Perform a security scan to confirm elimination of the injection flaw and monitor logs for suspicious SQL activity.

Generated by OpenCVE AI on August 28, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title Multiple Vulnerabilities in IBM Concert Software
First Time appeared Ibm
Ibm concert
CPEs cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:2.3.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm concert
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:53:37.759Z

Reserved: 2026-03-06T02:41:54.189Z

Link: CVE-2026-3627

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:49.063

Modified: 2026-08-28T22:16:49.063

Link: CVE-2026-3627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')