No analysis available yet.
Vendor Solution
IBM strongly recommends addressing these vulnerabilities now by upgrading to IBM Concert Software 2.0.0 Download IBM Concert Software 2.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27839 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7243699 |
|
Wed, 03 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:concert:*:*:*:*:*:*:*:* |
Tue, 02 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM Concert Software cross-site scripting | |
| First Time appeared |
Ibm
Ibm concert |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:concert:1.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm concert |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-02T20:14:11.755Z
Reserved: 2025-04-15T17:50:20.369Z
Link: CVE-2025-33082
Updated: 2025-09-02T20:12:57.675Z
Status : Analyzed
Published: 2025-09-01T15:15:34.440
Modified: 2025-09-03T16:05:38.653
Link: CVE-2025-33082
No data.
OpenCVE Enrichment
No data.
EUVD