Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CVE-2025-36253: IBM Concert uses weak encryption, puts sensitive data at risk
CVE-2025-36253 · published 6 months ago
Summary
IBM Concert versions 1.0.0 through 2.1.0 use outdated encryption methods, which could allow attackers to access sensitive information. This is a serious security risk for any organization using this software, as it could lead to unauthorized access to confidential data. To protect your data, update to a newer version of IBM Concert that uses more secure encryption methods.
What to do
- Update ibm concert to version 2.2.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | concert |
>= 1.0.0, < 2.2.0 cpe:2.3:a:ibm:concert:*:*:*:*:*:*:*:* |
Original advisory text
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
References
- https://www.ibm.com/support/pages/node/7257565 Vendor Advisory
Severity
7.5
High
CVSS 3.1: 7.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-759
Timeline
Published2 Feb 2026
Updated16 Aug 2026
First seen6 Mar 2026
Sources
CVE-2025-36253 · NVD
Monitor software like this
Free during beta