Junglewise Threat Intelligence

CVE-2025-36084: IBM Concert weak cryptographic algorithm

CVE-2025-36084 · Severity: medium · CVSS 5.9 · Published 2026-09-22

Technologies: IBM Concert. Vendors: IBM.

Executive brief

IBM Concert, a software platform, uses weaker-than-expected cryptographic algorithms to protect sensitive data. An attacker with network access could potentially decrypt information that is intended to remain confidential, compromising data security and compliance posture.

Technical details

IBM Concert versions 1.0.0 through 3.0.0 implement cryptographic algorithms that are weaker than industry standards, allowing attackers to decrypt sensitive information. The vulnerability is exploitable remotely without authentication, though the complexity suggests computational effort is required. No public exploitation has been reported.

Affected products

  • IBM Concert 1.0.0 through 3.0.0

Timeline

  • 2025-09-22: disclosed

References

Related threats