CVE-2025-36154: IBM Concert Software Cleartext Storage in a File or on Disk.
IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.
Other sources
IBM Concert Software stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36154?
CVE-2025-36154 has a medium severity due to the exposure of sensitive information in cleartext.
How do I fix CVE-2025-36154?
To mitigate CVE-2025-36154, upgrade IBM Concert Software to version 2.1.1 or later.
What kind of sensitive information is exposed in CVE-2025-36154?
CVE-2025-36154 exposes sensitive information that can include credentials or configuration data stored in cleartext.
Who is affected by CVE-2025-36154?
Users of IBM Concert versions 1.0.0 to 2.1.0 are affected by CVE-2025-36154 during recursive docker builds.
Can a local user exploit CVE-2025-36154?
Yes, a local user can exploit CVE-2025-36154 to access sensitive information stored in cleartext.