CVE-2025-36084Medium· 5.9▾ SunlitIBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Concert >= 1.0.0 <= 3.0.0IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1
Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12767Medium· 5.3Multiple Vulnerabilities in IBM Concert Software
CVE-2026-15915Medium· 6.2Multiple Vulnerabilities in IBM Concert Software
CVE-2026-16426Medium· 6.5Multiple Vulnerabilities in IBM Concert Software
CVE-2026-17472Critical· 9.6Multiple Vulnerabilities in IBM Concert Software
CVE-2026-17465Medium· 6.5Multiple Vulnerabilities in IBM Concert Software
CVE-2025-33147Medium· 5.9IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.