CVE-2025-33082: IBM Concert Software cross-site scripting
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Concert Software is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33082?
The severity of CVE-2025-33082 is classified as high due to its potential impact on user credentials and overall application security.
How do I fix CVE-2025-33082?
To fix CVE-2025-33082, upgrade to a version of IBM Concert Software beyond 1.1.0 where the vulnerability is addressed.
What type of vulnerability is CVE-2025-33082?
CVE-2025-33082 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary JavaScript code.
Who is affected by CVE-2025-33082?
All authenticated users of IBM Concert Software versions 1.0.0 through 1.1.0 are affected by CVE-2025-33082.
What can an attacker do with CVE-2025-33082?
An attacker exploiting CVE-2025-33082 could manipulate the web UI to execute malicious scripts, potentially leading to credential disclosure.