ZeroHour

CVE-2026-3627

moderate

Critical Unauthenticated SQL Injection in IBM Concert 1.0.0–2.3.1

CVSS 3.1
9.1 critical
EPSS
<1%p42
Published
()
Modified
AI analysis

IBM Concert versions 1.0.0 through 2.3.1 contain a SQL injection flaw (CWE-89) in the product's handling of back-end database queries. A remote attacker can send specially crafted SQL statements over the network without authentication or user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows the attacker to view, add, modify, or delete information stored in the back-end database, exposing or corrupting operational data managed by Concert. Any organization running IBM Concert 1.0.0 through 2.3.1 is affected, including both self-hosted and containerized enterprise deployments. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days, so no in-the-wild exploitation is known.

What to do: Inventory your environment for IBM Concert instances and verify running versions; upgrade any instance at version 2.3.1 or earlier to a fixed release once IBM publishes it in the corresponding IBM Security Bulletin. Until patching, restrict network access to Concert and its back-end database to trusted users and review database logs for anomalous or unexpected SQL queries. Continue monitoring the IBM advisory and CISA KEV for updates, as critical unauthenticated injection flaws often receive automated exploitation tooling once a PoC appears.

Affected
IBM Concert1.0.0 through 2.3.1 (inclusive)
Estimated exposure
moderatelikely on the order of 1,000–10,000 enterprise deployments (no public install-count or scan data available) — IBM Concert is a niche, enterprise-focused application-automation and resource-management product typically deployed inside corporate environments rather than as mass-market internet-facing software, so the affected base is estimated from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vendors
ibm
Products
concert
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.