CVE-2025-64645: Multiple Vulnerabilities in IBM Concert Software.
Published Dec 22, 2025
·Updated
IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.
Other sources
IBM Concert Software could allow a local user to escalate their privileges due to a race condition of a symbolic link.
— IBM
Affected Software
2 affected components
IBM Concert Software<=1.0.0-2.1.0
IBM Concert>=1.0.0<2.2.0
Remediation
Information
IBM strongly recommends addressing the vulnerabilities now by upgrading to IBM Concert Software 2.2.0
Download IBM Concert Software 2.2.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
Event History
Dec 22, 2025
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Dec 26, 2025
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64645?
CVE-2025-64645 has a moderate severity level as it allows local users to escalate privileges.
2
How do I fix CVE-2025-64645?
To mitigate CVE-2025-64645, upgrade IBM Concert Software to a version beyond 2.1.0.
3
What versions of IBM Concert Software are affected by CVE-2025-64645?
IBM Concert Software versions from 1.0.0 to 2.1.0 are vulnerable to CVE-2025-64645.
4
Who is impacted by CVE-2025-64645?
Local users of IBM Concert Software could be impacted by the privilege escalation in CVE-2025-64645.
5
Is CVE-2025-64645 a remote exploit?
No, CVE-2025-64645 is not a remote exploit as it requires local access to the system.