CVE-2025-13044
בינונית 6.2
תיאור (מקור, אנגלית)
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
מדדים
- CVSS 3.1
-
6.2 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-27/7/2026
- CWE
- CWE-340
מוצרים מושפעים
ibm: concert
קישורים
- https://www.ibm.com/support/pages/node/7268620 Vendor Advisory