cve-2026-6327

MEDIUM CVSS 4.3 opencve
Description

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

Timeline
Published
2026-09-23 16:16 UTC
Last Modified
2026-09-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N mitre
3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N nvd
3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-6327",
  "enrichment": {
    "created": "2026-09-23T17:30:06.830746+00:00",
    "updated": "2026-09-23T17:30:06.830752+00:00",
    "vendors": []
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
      "cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-23T15:50:11.529000+00:00",
    "description": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 4.3,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/6xxx/CVE-2026-6327.json",
    "references": [
      "https://www.ibm.com/support/pages/node/7288830"
    ],
    "title": "Multiple Vulnerabilities in IBM Concert Software",
    "updated": "2026-09-23T16:33:48.349000+00:00",
    "vendors": [
      "ibm",
      "ibm$PRODUCT$concert"
    ],
    "weaknesses": [
      "CWE-117"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2026-09-23T16:16:43.947000+00:00",
    "description": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 4.3,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-6327.json",
    "references": [
      "https://www.ibm.com/support/pages/node/7288830"
    ],
    "title": null,
    "updated": "2026-09-23T18:17:07.270000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-117"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-23T16:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "Multiple Vulnerabilities in IBM Concert Software",
              "old": null
            },
            "type": "title"
          },
          {
            "details": [
              "ibm",
              "ibm$PRODUCT$concert"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-117"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "ibm",
                "ibm$PRODUCT$concert"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.ibm.com/support/pages/node/7288830"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 4.3,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "bdbf074c-a3e1-459f-918b-005a03e10a69"
      },
      {
        "created": "2026-09-23T17:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "aa59f1fe-7871-4b6f-ae52-68b69ede1b1f"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-09-23T15:50:11.529000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 4.3,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {},
        "provider": null
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.ibm.com/support/pages/node/7288830"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Multiple Vulnerabilities in IBM Concert Software",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-09-23T17:17:15.963000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "ibm",
        "ibm$PRODUCT$concert"
      ],
      "providers": [
        "mitre"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-117"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-23T15:50:11.529000+00:00",
    "description": "IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Multiple Vulnerabilities in IBM Concert Software",
    "updated": "2026-09-23T16:33:35.624000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/6xxx/CVE-2026-6327.json",
    "weaknesses": []
  }
}
View JSON API Download JSON