CVE-2025-64646: IBM Concert

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

Affected products

  • IBM Concert: from 1.0.0, up to and including 2.2.0

Published 2026-03-25. Last modified 2026-06-17.