Information Disclosure Vulnerability in IBM Concert Software
CVE-2025-33084

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
1 September 2025

What is CVE-2025-33084?

A vulnerability in IBM Concert Software versions 1.0.0 to 1.1.0 could enable remote attackers to access sensitive information. This issue arises from improper implementation of HTTP Strict Transport Security, allowing exploitation through man-in-the-middle techniques. Organizations using these software versions should review their security configurations and consider applying the necessary patches to mitigate potential risks.

Affected Version(s)

Concert Software 1.0.0 <= 1.1.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.