Uncontrolled Directory Copying Vulnerability in IBM Concert Products
CVE-2025-36158

5.1MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
20 November 2025

What is CVE-2025-36158?

IBM Concert versions 1.0.0 to 2.0.0 contain a vulnerability that enables local users with appropriate permissions to potentially gain access to sensitive information through uncontrolled recursive directory copying. This flaw may allow unauthorized data exposure from certain files, highlighting the need for heightened security measures and prompt patching.

Affected Version(s)

Concert 1.0.0 <= 2.0.0

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36158 : Uncontrolled Directory Copying Vulnerability in IBM Concert Products