Clear Text Data Transmission Vulnerability in IBM Concert
CVE-2025-64648

5.9MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2025-64648?

IBM Concert versions 1.0.0 through 2.2.0 exhibit a vulnerability where sensitive data is transmitted in clear text, making it susceptible to interception by attackers. This flaw allows attackers to exploit man-in-the-middle techniques to capture and access confidential information, potentially leading to data breaches and unauthorized access. It is crucial for users to implement security measures to safeguard against such vulnerabilities.

Affected Version(s)

Concert 1.0.0 <= 2.2.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.