CVE-2025-64647: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Other sources
IBM concert software uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64647?
CVE-2025-64647 is considered a high severity vulnerability due to the use of weaker cryptographic algorithms that can facilitate decryption of sensitive information.
How do I fix CVE-2025-64647?
To fix CVE-2025-64647, upgrade IBM Concert Software to version 2.2.1 or later, which utilizes stronger cryptographic algorithms.
What versions of IBM Concert Software are affected by CVE-2025-64647?
IBM Concert Software versions 1.0.0 through 2.2.0 are affected by CVE-2025-64647.
What kind of information is at risk with CVE-2025-64647?
CVE-2025-64647 puts highly sensitive information at risk due to the weaknesses in the cryptographic algorithms used by the software.
Who should be concerned about CVE-2025-64647?
Organizations using IBM Concert Software versions 1.0.0 to 2.2.0 should be particularly concerned about CVE-2025-64647 and take immediate action to upgrade.