
CVE-2025-13044 IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. https://www.cve.org/CVERecord?id=CVE-2025-13044
Post summary
The CVE details a predictability issue with temporary files in IBM Concert that permits local users to perform a symlink attack and overwrite arbitrary files; no exploitation, patch, or PoC information is included.


