Unauthorized Action Vulnerability in IBM Concert by IBM
CVE-2025-36438

5.1MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2025-36438?

IBM Concert versions 1.0.0 through 2.2.0 are impacted by a vulnerability that allows privileged users to carry out unauthorized actions. This occurs due to inadequate restrictions on channel communications, which fail to enforce intended endpoint limitations. Users must ensure that all applicable patches are applied to mitigate potential risks and safeguard their systems.

Affected Version(s)

Concert 1.0.0 <= 2.2.0

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.