Executive brief
IBM Concert is a software platform used by enterprises for application development and integration. A flaw in how the product processes user-supplied regular expressions allows a remote attacker to cause the application to consume excessive system resources and become unresponsive, disrupting business operations without requiring authentication.
Technical details
The vulnerability is a regular expression denial of service (ReDoS) flaw affecting IBM Concert versions 1.0.0 through 3.0.0. An unauthenticated remote attacker can craft a malicious regular expression that triggers catastrophic backtracking, causing excessive CPU and memory consumption. The attack requires network access but no special privileges or user interaction.
Affected products
- IBM Concert 1.0.0 through 3.0.0
Timeline
- 2026-09-22: disclosed