IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.
Exploitability
AV:LAC:LPR:NUI:NScope
S:UImpact
C:LI:LA:N5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NOther