CVE Vulnerabilities

CVE-2025-13044

Generation of Predictable Numbers or Identifiers

Published: Apr 07, 2026 | Modified: Apr 07, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

Weakness

The product uses a scheme that generates numbers or identifiers that are more predictable than required.

Affected Software

NameVendorStart VersionEnd Version
ConcertIbm1.0.0 (including)2.2.0 (including)

References