CVE-2025-33015: IBM Concert
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
Affected products
- IBM Concert: from 1.0.0, before 2.2.0 (fixed in 2.2.0)
Published 2026-01-20. Last modified 2026-06-17.