CVE-2025-36158: IBM Concert Information Disclosure
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.
Other sources
IBM Concert Software could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36158?
CVE-2025-36158 is rated as a medium severity vulnerability affecting IBM Concert Software.
How do I fix CVE-2025-36158?
To fix CVE-2025-36158, update IBM Concert Software to the latest version beyond 2.0.0.
What is the impact of CVE-2025-36158 on IBM Concert Software?
CVE-2025-36158 allows a local user to access sensitive information from files due to uncontrolled recursive directory copying.
Which versions of IBM Concert Software are affected by CVE-2025-36158?
CVE-2025-36158 affects IBM Concert Software versions 1.0.0 through 2.0.0 inclusive.
Who is impacted by CVE-2025-36158?
Local users with specific permissions on affected versions of IBM Concert Software are impacted by CVE-2025-36158.