CNNVD-202601-3219 Information

CNNVD ID

CNNVD-202601-3219

CVE-2025-33015

  • CNNVD Published: 2026-01-20

Description (Chinese)

IBM Concert是美国国际商业机器(IBM)公司的一种新工具。使用生成式 AI 来帮助管理复杂的云原生应用程序。 IBM Concert 1.0.0版本至2.1.0版本存在代码问题漏洞,该漏洞源于未验证上传到Web界面的文件内容,可能导致恶意文件上传。

Description (English)

IBM Concert is a new tool for IBM. Use the Generating AI to help manage complex cloud raw applications. There is a code gap between IBM Concert 1.0.0 and 2.1.0, which stems from the unverified uploading of documents to the Web interface, which may lead to the uploading of malicious documents.

Hazard Level

Medium

Vulnerability Type

代码问题

Affected Vendor

国际商业机器

Published

2026-01-20

Last Modified

2026-02-24

References

https://www.ibm.com/support/pages/node/7257006

Patch

https://www.ibm.com/products/concert

Share on: