Executive brief
IBM Concert is a software platform used for enterprise application integration and business process automation. A SQL injection vulnerability allows remote attackers to send malicious SQL statements to the backend database, enabling them to view, modify, or delete sensitive business data without authentication.
Technical details
IBM Concert versions 1.0.0 through 2.3.1 are vulnerable to SQL injection in database query handling. The vulnerability stems from insufficient input validation or parameterization of SQL queries, allowing attackers to inject arbitrary SQL statements. The attack is network-accessible with no authentication required. A successful exploit grants an attacker read, write, and delete access to the entire backend database, potentially exposing or corrupting critical business data. IBM has addressed this issue in version 3.0.0 or later.
Affected products
- IBM Concert 1.0.0 through 2.3.1
Timeline
- 2026-08-28: disclosed