CVE-2024-49354 Details
Description
IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.
A vulnerability in IBM Concert versions 1.0.0, 1.0.1, and 1.0.2 allows for sensitive information disclosure through specially crafted API calls. This issue arises from incompatible policies that expose sensitive data.
Users are advised to upgrade to IBM Concert version 1.0.2.1, available through the IBM Entitled Registry. After upgrading, it is recommended to rotate any end user or application secrets used within Concert.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7174120 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-213 | Exposure of Sensitive Information Due to Incompatible Policies | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm concert | 1.0.0 1.0.1 1.0.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | Initial Analysis | [email protected] |
| Jan 18, 2025 | New CVE Received | [email protected] |