CVE-2025-36083Medium· 6.2▾ SunlitIBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
IBM Concert Software
1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.
concert >= 1.0.0, < 2.1.0Upgrade past the affected range:
concert 2.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-36081Medium· 5.3IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.
CVE-2025-36085Medium· 5.4IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF)
CVE-2026-6544Medium· 6.2IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
CVE-2026-6928Critical· 9.8IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed
CVE-2026-6935High· 7.8IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution
CVE-2026-6730Critical· 9.8IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking