CVE-2024-52891

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.
References
Link Resource
https://www.ibm.com/support/pages/node/7180303 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.3:*:*:*:*:*:*:*

History

18 Jul 2025, 13:39

Type Values Removed Values Added
Summary
  • (es) IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1 y 1.0.3 podría permitir que un usuario autenticado inyecte información maliciosa u obtenga información de archivos de registro debido a una neutralización incorrecta de los registros.
First Time Ibm concert
Ibm
References () https://www.ibm.com/support/pages/node/7180303 - () https://www.ibm.com/support/pages/node/7180303 - Vendor Advisory
CWE CWE-116
CPE cpe:2.3:a:ibm:concert:1.0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.2:*:*:*:*:*:*:*

07 Jan 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 12:15

Updated : 2025-07-18 13:39


NVD link : CVE-2024-52891

Mitre link : CVE-2024-52891

CVE.ORG link : CVE-2024-52891


JSON object : View

Products Affected

ibm

  • concert
CWE
CWE-117

Improper Output Neutralization for Logs

CWE-116

Improper Encoding or Escaping of Output