CVE-2025-36154
MEDIUMDescription
IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | concert |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-36154? +
How severe is CVE-2025-36154? +
What products are affected by CVE-2025-36154? +
How do I check if I'm vulnerable to CVE-2025-36154? +
Related Vulnerabilities
PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account …
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials …
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow …
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, …
A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the …
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of …