Executive brief
IBM Concert is business software that handles workflow and application integration. A server-side request forgery vulnerability allows authenticated users to send unauthorized network requests from the system, enabling attackers to enumerate internal networks, access restricted resources, or launch further attacks on connected systems.
Technical details
A server-side request forgery (SSRF) vulnerability in IBM Concert versions 1.0.0 through 3.0.0 allows authenticated attackers to craft requests that the system processes on their behalf. This permits network enumeration and can serve as a pivot point for lateral movement or access to internal services. The vulnerability requires prior authentication to exploit.
Affected products
- IBM Concert 1.0.0 through 3.0.0
Timeline
- 2026-09-22: disclosed