IBM Concert是美国国际商业机器(IBM)公司的一种新工具。使用生成式 AI 来帮助管理复杂的云原生应用程序。 IBM Concert 1.0.5及之前版本存在路径遍历漏洞,该漏洞源于处理包含点序列的URL请求不当,可能导致路径遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Concert Software | 1.0.0 ~ 1.0.5 |
cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-55909 | 6.5 MEDIUM | IBM Concert Software denial of service |
| CVE-2024-55910 | 6.5 MEDIUM | IBM Concert Software server-side request forgery |
| CVE-2024-55912 | 5.9 MEDIUM | IBM Concert Software information disclosure |
No comments yet