CVE-2025-13044: Multiple Vulnerabilities in IBM Concert Software
Published Apr 6, 2026
·Updated
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Other sources
IBM Concert Software creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
— IBM
Affected Software
2 affected components
IBM Concert Software<=1.0.0-2.2.0
IBM Concert>=1.0.0<=2.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 2.3.1
Event History
Apr 6, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Apr 7, 2026
CVE Published
via MITRE·01:07 AM
Data Sourced
via MITRE·01:07 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software