CVE-2025-0656: IBM Concert Software cross-site scripting
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
This issue represents a potential PII concern. If applications were printing or logging a context containing gRPC metadata, the affected versions will contain all the metadata, which may include private information.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0656?
CVE-2025-0656 is classified as a cross-site scripting (XSS) vulnerability, which can lead to significant security risks.
How do I fix CVE-2025-0656?
To fix CVE-2025-0656, it is recommended to update IBM Concert Software to the latest version that patches this vulnerability.
Who is affected by CVE-2025-0656?
CVE-2025-0656 affects users of IBM Concert Software versions 1.0.0 through 1.1.0.
What can an attacker do with CVE-2025-0656?
An attacker exploiting CVE-2025-0656 can execute arbitrary JavaScript code within the application, potentially leading to credential disclosure.
Is CVE-2025-0656 an authenticated or unauthenticated vulnerability?
CVE-2025-0656 is an unauthenticated vulnerability, allowing any user to exploit it without needing to log in.