CVE-2025-12708: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.
Other sources
IBM Concert Software contains hard-coded credentials that could be obtained by a local user.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12708?
CVE-2025-12708 is considered a medium severity vulnerability due to the presence of hard-coded credentials in IBM Concert Software.
How do I fix CVE-2025-12708?
To fix CVE-2025-12708, replace the hard-coded credentials with securely generated user-specific credentials.
Which versions are affected by CVE-2025-12708?
CVE-2025-12708 impacts IBM Concert Software versions 1.0.0 through 2.2.0.
Who can exploit CVE-2025-12708?
CVE-2025-12708 can be exploited by local users who have access to the affected IBM Concert Software versions.
What are the risks associated with CVE-2025-12708?
The risks associated with CVE-2025-12708 include unauthorized access to sensitive information due to the exposure of hard-coded credentials.