Skip to main content

Generation of Predictable Numbers or Identifiers

CVE-2025-13044

Severity Medium
Score 6.2/10

Summary

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-340 - Generation of Predictable Numbers or Identifiers

The product uses a scheme that generates numbers or identifiers that are more predictable than required.

References

Advisory Timeline

  • Published