CVE-2025-33085: IBM Concert Software vulnerability
Published Dec 22, 2025
·Updated
IBM Concert Software could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
Affected Software
1 affected component
IBM Concert Software<=1.0.0-2.1.0
Event History
Dec 22, 2025
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33085?
CVE-2025-33085 is considered a medium severity vulnerability due to the potential for sensitive information disclosure.
2
How do I fix CVE-2025-33085?
To fix CVE-2025-33085, ensure that the SameSite attribute is correctly configured for cookies in IBM Concert Software.
3
Which versions of IBM Concert Software are affected by CVE-2025-33085?
CVE-2025-33085 affects IBM Concert Software versions from 1.0.0 up to and including 2.1.0.
4
What type of issue does CVE-2025-33085 represent?
CVE-2025-33085 represents a cookie security issue where sensitive information could be exposed.
5
Is there a workaround for CVE-2025-33085?
A workaround for CVE-2025-33085 includes setting the SameSite attribute for cookies in the application code.