CVE-2025-36158 Details
Description
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.
A vulnerability exists in IBM Concert Software versions 1.0.0 through 2.0.0, allowing a local user with specific permissions to access sensitive information from files. This issue arises from uncontrolled recursive directory copying, which could be exploited to leak confidential data.
Users are advised to upgrade to IBM Concert Software version 2.1.0. This version can be downloaded from the Container software library section of the IBM Entitled Registry (ICR) and users should follow the provided installation instructions based on their deployment type.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7252019 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-674 | Uncontrolled Recursion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm concert | >= 1.0.0, < 2.1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2025 | Initial Analysis | [email protected] |
| Nov 20, 2025 | New CVE Received | [email protected] |