CVE-2025-64648: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM Concert software transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64648?
CVE-2025-64648 is classified as a medium severity vulnerability due to the potential exposure of sensitive data during transmission.
How do I fix CVE-2025-64648?
To mitigate CVE-2025-64648, ensure that you upgrade to the latest version of IBM Concert Software that addresses this vulnerability.
What versions of IBM Concert Software are affected by CVE-2025-64648?
IBM Concert Software versions 1.0.0 through 2.2.0 are affected by CVE-2025-64648.
What type of attacks can exploit CVE-2025-64648?
CVE-2025-64648 can be exploited using man-in-the-middle attacks to intercept and access sensitive information transmitted in clear text.
Is it safe to use IBM Concert Software versions 1.0.0 to 2.2.0?
It is not safe to use IBM Concert Software versions 1.0.0 to 2.2.0 due to the vulnerabilities associated with CVE-2025-64648.