CVE-2025-27909
5.4MEDIUMIBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted
Published: 8/18/2025Updated: 8/21/2025
Description
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
AI AnalysisPowered by AI
Affected Products
ibmconcert
References
- https://www.ibm.com/support/pages/node/7242354Vendor Advisory