CVE-2025-33083: IBM Concert Software cross-site scripting
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Concert Software is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33083?
The severity of CVE-2025-33083 is classified as high due to its potential to allow unauthorized JavaScript code execution.
How do I fix CVE-2025-33083?
To fix CVE-2025-33083, upgrade IBM Concert Software to version 1.1.1 or later, which addresses this cross-site scripting vulnerability.
Who is affected by CVE-2025-33083?
CVE-2025-33083 affects users of IBM Concert Software versions 1.0.0 through 1.1.0.
What are the risks associated with CVE-2025-33083?
The risks associated with CVE-2025-33083 include potential credential disclosure and alteration of the Web UI functionality.
Is there a workaround for CVE-2025-33083?
Currently, there are no documented workarounds for CVE-2025-33083 besides upgrading to a patched version.