Access Control Flaw in IBM Concert Affects Sensitive Data Protection
CVE-2025-36440

5.1MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2025-36440?

IBM Concert versions 1.0.0 to 2.2.0 are affected by an access control vulnerability that allows a local user to disclose sensitive information due to ineffective function-level access control mechanisms. This shortcoming could lead to unauthorized access to confidential data, highlighting the necessity for immediate remediation to safeguard user information.

Affected Version(s)

Concert 1.0.0 <= 2.2.0

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.