CVE-2025-64646
IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-14
- Published
- 2026-03-25
- Last modified
- 2026-03-26
Affected products
- IBM Concert
Weakness type
Related vulnerabilities
- CVE-2026-48984 — pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap
- CVE-2023-32100 — Key duplication in GSDK
- CVE-2023-32099 — Key duplication in GSDK
- CVE-2023-32098 — Key duplication in GSDK
- CVE-2023-32097 — Key duplication in GSDK
- CVE-2023-32096 — Key duplication in GSDK
- CVE-2023-2481 — Key duplication in GSDK
- CVE-2023-1132 — Key duplication in GSDK