IBM Concert Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in IBM Concert Software versions 1.0.0 through 2.0.0, allowing the disclosure of sensitive server information via HTTP response headers. This information could be leveraged to conduct further attacks against the system.

Impact

Exposing sensitive server information could facilitate additional attacks on the system.

Remediation

Users are advised to upgrade to IBM Concert Software version 2.1.0. This version can be downloaded from the Container software library section of the IBM Entitled Registry (ICR) and installed following the provided instructions for the type of deployment.

Added: Nov 20, 2025, 10:18 PM
Updated: Nov 20, 2025, 10:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.