cve-2026-6327
MEDIUM CVSS 4.3 opencve
Description
IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Timeline
- Published
- 2026-09-23 16:16 UTC
- Last Modified
- 2026-09-23
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
mitre | ||
| 3.1 | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
nvd | ||
| 3.1 | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-6327",
"enrichment": {
"created": "2026-09-23T17:30:06.830746+00:00",
"updated": "2026-09-23T17:30:06.830752+00:00",
"vendors": []
},
"mitre": {
"cpes": [
"cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
],
"created": "2026-09-23T15:50:11.529000+00:00",
"description": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 4.3,
"vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/6xxx/CVE-2026-6327.json",
"references": [
"https://www.ibm.com/support/pages/node/7288830"
],
"title": "Multiple Vulnerabilities in IBM Concert Software",
"updated": "2026-09-23T16:33:48.349000+00:00",
"vendors": [
"ibm",
"ibm$PRODUCT$concert"
],
"weaknesses": [
"CWE-117"
]
},
"nvd": {
"cpes": [],
"created": "2026-09-23T16:16:43.947000+00:00",
"description": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 4.3,
"vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-6327.json",
"references": [
"https://www.ibm.com/support/pages/node/7288830"
],
"title": null,
"updated": "2026-09-23T18:17:07.270000+00:00",
"vendors": [],
"weaknesses": [
"CWE-117"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-23T16:00:00+00:00",
"data": [
{
"details": {
"new": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "Multiple Vulnerabilities in IBM Concert Software",
"old": null
},
"type": "title"
},
{
"details": [
"ibm",
"ibm$PRODUCT$concert"
],
"type": "first_time"
},
{
"details": {
"added": [
"CWE-117"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"ibm",
"ibm$PRODUCT$concert"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.ibm.com/support/pages/node/7288830"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 4.3,
"vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "bdbf074c-a3e1-459f-918b-005a03e10a69"
},
{
"created": "2026-09-23T17:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "aa59f1fe-7871-4b6f-ae52-68b69ede1b1f"
}
],
"cpes": {
"data": [
"cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
],
"providers": [
"mitre"
]
},
"created": {
"data": "2026-09-23T15:50:11.529000+00:00",
"provider": "mitre"
},
"description": {
"data": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 4.3,
"vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {},
"provider": null
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.ibm.com/support/pages/node/7288830"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Multiple Vulnerabilities in IBM Concert Software",
"provider": "mitre"
},
"updated": {
"data": "2026-09-23T17:17:15.963000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"ibm",
"ibm$PRODUCT$concert"
],
"providers": [
"mitre"
]
},
"weaknesses": {
"data": [
"CWE-117"
],
"providers": [
"mitre",
"nvd"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-23T15:50:11.529000+00:00",
"description": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": "Multiple Vulnerabilities in IBM Concert Software",
"updated": "2026-09-23T16:33:35.624000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/6xxx/CVE-2026-6327.json",
"weaknesses": []
}
}