Product
IBM Concert versions 1.0.0 through 2.3.1 are vulnerable to a remote SQL injection attack, allowing unauthenticated attackers to query, modify, or delete data in the back-end database.