Description
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27737 | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7242354 |
|
History
Thu, 21 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-697 | |
| CPEs | cpe:2.3:a:ibm:concert:*:*:*:*:*:*:*:* |
Mon, 18 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains. | |
| Title | IBM Concert Software cross-origin resource sharing | |
| First Time appeared |
Ibm
Ibm concert |
|
| Weaknesses | CWE-942 | |
| CPEs | cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:concert:1.0.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm concert |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-18T14:12:36.834Z
Reserved: 2025-03-10T17:14:11.136Z
Link: CVE-2025-27909
Updated: 2025-08-18T14:12:26.833Z
Status : Analyzed
Published: 2025-08-18T14:15:28.550
Modified: 2025-08-21T20:56:49.000
Link: CVE-2025-27909
No data.
OpenCVE Enrichment
No data.
EUVD