CVE-2025-33100

MEDIUM

IBM Concert Software <1.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Scores

CVSS v3 6.2
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
ibm/concert 1.0.0 - 2.0.0
Published Aug 18, 2025
Tracked Since Feb 18, 2026