IBM Concert Sensitive Information Disclosure Vulnerability
Vulnerability
A vulnerability exists in IBM Concert Software versions 1.0.0 through 2.0.0, allowing the disclosure of sensitive server information via HTTP response headers. This information could be leveraged to conduct further attacks against the system.
Impact
Exposing sensitive server information could facilitate additional attacks on the system.
Remediation
Users are advised to upgrade to IBM Concert Software version 2.1.0. This version can be downloaded from the Container software library section of the IBM Entitled Registry (ICR) and installed following the provided instructions for the type of deployment.
Added: Nov 20, 2025, 10:18 PM
Updated: Nov 20, 2025, 10:18 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
7.7relevance
1.1threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
