Generation of Predictable Numbers or Identifiers
CVE-2025-13044
Summary
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-340 - Generation of Predictable Numbers or Identifiers
The product uses a scheme that generates numbers or identifiers that are more predictable than required.
References
Advisory Timeline
- Published