CVE-2024-43181 PUBLISHED

Multiple Vulnerabilities in IBM Concert Software

Assigner: ibm
Reserved: 07.08.2024 Published: 04.02.2026 Updated: 05.02.2026

IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 6.3

Product Status

Vendor IBM
Product Concert
Versions
  • affected from 1.0.0 to 2.1.0 (incl.)

Solutions

The recommended solution to address this vulnerability is to upgrade IBM Db2 Big SQL to version 8.2 or later available on IBM Cloud Pak for Data 5.2 or later by following the instructions for Upgrading Cloud Pak for Data https://www.ibm.com/docs/en/cloud-paks/cp-data/5.2.x  and Upgrading the Db2 Big SQL https://www.ibm.com/docs/en/cloud-paks/cp-data/5.2.x  service.

References

Problem Types

  • CWE-613 Insufficient Session Expiration CWE