CVE-2025-36150: IBM Concert Information Disclosure
IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Concert Software uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36150?
The severity of CVE-2025-36150 is considered high due to the potential for data decryption.
How do I fix CVE-2025-36150?
To fix CVE-2025-36150, upgrade IBM Concert Software to version 2.0.1 or later.
What types of information are affected by CVE-2025-36150?
CVE-2025-36150 can impact highly sensitive information that relies on cryptographic protection.
Who is affected by CVE-2025-36150?
Organizations using IBM Concert Software versions 1.0.0 to 2.0.0 are affected by CVE-2025-36150.
What are the potential consequences of CVE-2025-36150?
The potential consequences of CVE-2025-36150 include unauthorized access to sensitive information through decryption.