Privilege Escalation Vulnerability in IBM Concert Product
CVE-2025-64645
7.7HIGH
What is CVE-2025-64645?
IBM Concert versions 1.0.0 through 2.1.0 are susceptible to a local user exploitation scenario that arises from a race condition involving symbolic links. This vulnerability could potentially allow unauthorized users to escalate their privileges within the system, leading to unauthorized access and control.
Affected Version(s)
Concert 1.0.0 <= 2.1.0
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved