Remote Information Disclosure and Unauthorized Actions in IBM Concert Product
CVE-2025-33089
6.5MEDIUM
What is CVE-2025-33089?
IBM Concert versions 1.0.0 through 2.1.0 are susceptible to vulnerabilities that may allow remote attackers to gain access to sensitive information and execute unauthorized actions. This is due to the presence of hard-coded user credentials within the system, which could be exploited to compromise user data and operational integrity.
Affected Version(s)
Concert 1.0.0 <= 2.1.0