CVE 5.9 MEDIUM

IBM Concert Software information disclosure_CVE-2025-33084

5.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

Basic Information

ID CVE-2025-33084
Source ibm
Published Sep 1, 2025 at 14:20

Affected Product

Vendor IBM
Product Concert Software
Version 1.0.0
Affected Versions IBM Concert Software 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.