{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-6928",
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "state": "PUBLISHED",
        "assignerShortName": "ibm",
        "dateReserved": "2026-04-23T17:54:01.469Z",
        "datePublished": "2026-09-23T20:54:55.147Z",
        "dateUpdated": "2026-09-23T20:54:55.147Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
                "shortName": "ibm",
                "dateUpdated": "2026-09-23T20:54:55.147Z"
            },
            "title": "Multiple Vulnerabilities in IBM Concert Software",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-416",
                            "description": "CWE-416 Use After Free",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "IBM",
                    "product": "Concert",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "1.0.0",
                            "lessThanOrEqual": "3.0.0",
                            "versionType": "semver"
                        }
                    ],
                    "cpes": [
                        "cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
                        "cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.ibm.com/support/pages/node/7288830",
                    "tags": [
                        "vendor-advisory",
                        "patch"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.8,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1\n\n\n\nDownload IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1</p><p>Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry (<a href=\"https://myibm.ibm.com/products-services/containerlibrary\" rel=\"noopener noreferrer nofollow\">ICR</a>) and follow <a href=\"https://www.ibm.com/docs/en/concert?topic=installing-preparing-run-installs-from-private-container-registry\" rel=\"noopener noreferrer nofollow\">installation instructions</a> depending on the type of deployment.</p>"
                        }
                    ]
                }
            ]
        }
    }
}