PT-2025-33654 · Ibm · Ibm Concert

Published

2025-08-18

·

Updated

2025-08-18

·

CVE-2025-27909

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: IBM Concert Software versions 1.0.0 through 1.1.0
Description: IBM Concert Software is susceptible to a cross-origin resource sharing (CORS) issue. This configuration allows an attacker to potentially perform privileged actions because the domain name is not restricted to trusted domains.
Recommendations: IBM Concert Software versions prior to 1.2.0 should be updated.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-27909

Affected Products

Ibm Concert