Impact
The vulnerability allows an unauthorized user to inject arbitrary content into log files of IBM Concert Software. This log injection flaw stems from improper neutralization of special elements when data is written to logs. An attacker could insert crafted strings that change log entries, potentially concealing malicious activity or exfiltrating sensitive information that is read from logs.
Affected Systems
Affected products are IBM Concert Software versions 1.0.0 through 3.0.0, inclusive. The official fix is to upgrade to version 3.0.1.1, which addresses the improper neutralization logic.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS data are not available, and the vulnerability is not listed in CISA KEV. Because the flaw facilitates injection of data into logs by an unauthorized user, an attacker may exploit it from a remote application endpoint that accepts user input. The risk lies primarily in log integrity and potential information disclosure rather than in direct data compromise or denial of service.
OpenCVE Enrichment