CVE-2024-43177: IBM Concert

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Affected products

  • IBM Concert: version 1.0.0 only; version 1.0.1 only

Published 2024-10-22. Last modified 2026-06-17.