Impact
The vulnerability is a classic SQL injection flaw found in IBM Concert 1.0.0 through 2.3.1. A remote attacker can craft SQL statements that the application blindly executes against its back‑end database. This allows the attacker to read, insert, update, or delete database records, compromising the confidentiality, integrity, and availability of the stored information.
Affected Systems
Affected products are IBM Concert Software, versions 1.0.0 to 2.3.1. The update to version 3.0.0 has been released to address the issue. No specific patches for earlier releases are listed, so upgrading to the new major release is required.
Risk and Exploitability
The CVSS score of 9.1 signals a critical vulnerability. The EPSS is not available, and the vulnerability is not on the CISA KEV list, but the high CVSS encourages urgency. The lack of an official workaround means the vulnerability must be resolved by upgrading. Remote exploitation is inferred as the attack vector, based on the ability to send crafted SQL statements over the network to the application’s interface.
OpenCVE Enrichment