CVE-2025-36159: IBM Concert Improper Log Neutralization
Published Nov 20, 2025
·Updated
IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.
Affected Software
2 affected components
IBM Concert>=1.0.0<2.1.0
IBM Concert Software<=1.0.0-2.2.0
Remediation
Information
Remediation/Fixes IBM strongly recommends addressing the vulnerabilities now by upgrading to IBM Concert Software 2.1.0 Download IBM Concert Software 2.1.0 from Container software library section of IBM Entitled Registry ( ICR ) and follow installation instructions depending on the type of deployment.
Event History
Nov 20, 2025
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 23, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-36159?
CVE-2025-36159 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-36159?
To fix CVE-2025-36159, upgrade to a version of IBM Concert Software that is not within the affected range of 1.0.0-2.0.0.
3
What are the potential impacts of CVE-2025-36159?
CVE-2025-36159 could allow local users to forge log files, impersonating other users or concealing their own identity.
4
Who is affected by CVE-2025-36159?
Users of IBM Concert Software versions 1.0.0 through 2.0.0 are affected by CVE-2025-36159.
5
Is CVE-2025-36159 exploitable remotely?
CVE-2025-36159 is not remotely exploitable as it requires local user access to exploit.