CVE-2024-43181: IBM Concert

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Affected products

  • IBM Concert: from 1.0.0, before 2.2.0 (fixed in 2.2.0)

Published 2026-02-04. Last modified 2026-06-17.