CVE-2024-43177: IBM Concert
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
Affected products
- IBM Concert: version 1.0.0 only; version 1.0.1 only
Published 2024-10-22. Last modified 2026-06-17.