Executive brief
IBM Concert, a software platform, uses weaker-than-expected cryptographic algorithms to protect sensitive data. An attacker with network access could potentially decrypt information that is intended to remain confidential, compromising data security and compliance posture.
Technical details
IBM Concert versions 1.0.0 through 3.0.0 implement cryptographic algorithms that are weaker than industry standards, allowing attackers to decrypt sensitive information. The vulnerability is exploitable remotely without authentication, though the complexity suggests computational effort is required. No public exploitation has been reported.
Affected products
- IBM Concert 1.0.0 through 3.0.0
Timeline
- 2025-09-22: disclosed