Executive brief
IBM Concert is a software platform that manages collaborative workspaces and data storage. A remote attacker with valid credentials can trigger a denial of service by exploiting improper enforcement of storage limits, potentially disrupting availability for all users. The vulnerability affects Concert versions 1.0.0 through 3.0.0 and requires authentication to exploit.
Technical details
A remote authenticated attacker can cause denial of service in IBM Concert due to improper enforcement of storage limits. The vulnerability is in the storage management component and requires valid user credentials to exploit. A patch is available in version 3.0.1.1 or later.
Affected products
- IBM Concert 1.0.0 through 3.0.0
Timeline
- 2026-09-22: disclosed