medium · CVSS v3 6.5
CVE-2026-17465
IBM Concert versions 1.0.0 through 3.0.0 are vulnerable to a denial-of-service attack. An authenticated user can trigger the flaw by exceedi
Overview
IBM Concert versions 1.0.0 through 3.0.0 are vulnerable to a denial-of-service attack. An authenticated user can trigger the flaw by exceeding storage limits, causing the application to become unresponsive. This impacts availability for organizations running these versions.
Description
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
Impact
Denial of service reduces availability of the IBM Concert application, disrupting business processes. The vulnerability is exploitable only by authenticated users, so internal staff or compromised accounts are the primary threat actors. Defenders should monitor for abnormal resource consumption and ensure proper storage quotas are enforced.
Remediation
Apply the latest IBM Concert patch that enforces storage limits, or upgrade to a supported version beyond 3.0.0. If patching is not immediately possible, configure application-level resource limits and monitor disk usage to prevent exhaustion. Disable or restrict privileged accounts that can trigger the flaw until remediation.
Risk context
Severity is medium (CVSS 6.5). No EPSS data available. The risk is moderate; defenders should prioritize patching but can tolerate a short window if mitigations are in place.
Affected products
- IBM Concert 1.0.0
- IBM Concert 2.0.0
- IBM Concert 3.0.0
Scores
- Severity
- medium
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —