Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ibm/Concert

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

IBM Concert versions 1.0.0 through 2.2.0 have a vulnerability where temporary files are created with predictable names. This flaw allows local users to perform symlink attacks to overwrite arbitrary files. The vulnerability does not impact confidentiality or availability but can lead to integrity compromise. It has a CVSS 3.1 score of 6.2, indicating medium severity.

Join the discussion

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

Join the discussion

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

Join the discussion

IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.

Join the discussion

IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

Join the discussion

CVE-2024-51451 is a medium severity vulnerability in IBM Concert versions 1.0.0 through 2.1.0 caused by improper validation of HOST headers, leading to HTTP header injection. This flaw allows attackers to perform cross-site scripting (XSS), cache poisoning, or session hijacking without requiring authentication or user interaction. The vulnerability impacts confidentiality and integrity but not availability. Exploitation is remotely feasible with low complexity. European organizations using IBM Concert, especially in countries with significant IBM enterprise deployments, are at risk. Mitigations include strict validation and sanitization of HOST headers, deploying web application firewalls with custom rules, and monitoring HTTP traffic for anomalies.

Join the discussion

CVE-2024-43181 is a medium severity vulnerability in IBM Concert versions 1.0.0 through 2.1.0 where sessions are not invalidated upon user logout. This insufficient session expiration (CWE-613) flaw allows an authenticated user to potentially impersonate another user by reusing a session token after logout. The vulnerability requires prior authentication but no user interaction beyond logout. Exploitation could lead to limited confidentiality, integrity, and availability impacts. No known exploits are currently reported in the wild. European organizations using IBM Concert should prioritize patching or implementing compensating controls to prevent session reuse.

Join the discussion

IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

Join the discussion

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Join the discussion

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

Join the discussion

Showing 1 to 10 of 22 results

Filters:Package: pkg:github/ibm/Concert
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses