Information Disclosure Vulnerability in IBM Concert Software
CVE-2025-33084
5.9MEDIUM
What is CVE-2025-33084?
A vulnerability in IBM Concert Software versions 1.0.0 to 1.1.0 could enable remote attackers to access sensitive information. This issue arises from improper implementation of HTTP Strict Transport Security, allowing exploitation through man-in-the-middle techniques. Organizations using these software versions should review their security configurations and consider applying the necessary patches to mitigate potential risks.
Affected Version(s)
Concert Software 1.0.0 <= 1.1.0
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved