CVE-2025-36160: IBM Concert
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.
Affected products
- IBM Concert: from 1.0.0, before 2.1.0 (fixed in 2.1.0)
Published 2025-11-20. Last modified 2026-06-17.