CVE-2025-36160: IBM Concert Information Disclosure
IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.
Other sources
IBM Concert Software could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36160?
The severity of CVE-2025-36160 is classified as high due to the potential for sensitive information disclosure that could facilitate further attacks.
How do I fix CVE-2025-36160?
To fix CVE-2025-36160, update IBM Concert Software to the latest version beyond 2.0.0.
What type of information can be disclosed by CVE-2025-36160?
CVE-2025-36160 can disclose sensitive server information through HTTP response headers.
Which versions of IBM Concert Software are affected by CVE-2025-36160?
IBM Concert Software versions 1.0.0 through 2.0.0 are affected by CVE-2025-36160.
What potential risks are associated with CVE-2025-36160?
The risks associated with CVE-2025-36160 include unauthorized information access that can lead to further attacks against the system.